Infesting you with Virus News
 

Vulnerabilities

WebKit in Apple Safari prior to 4.0 DDOS vulnerability (PC1-2009-1555)

Overview

Vulnerability chart

Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
101 vulnerabilities(-y) found between 8 December, 2003 and 21 September, 2009.
Safari is a web browser  developed by Apple Inc. Apple Safari is the... more
See also: Safari, The Apple Safari
1 files found: SAFARI.EXE... more
WebKit in Apple Safari prior to 4.0 does not suitably cope with constant (aka const) declarations in a type-conversion operation throughout JavaScript exception handling.
Remote Access
Yes, patch
is available
Patch is easy
to implement

References to Advisories, Solutions, and Tools

Description:

This lets remote attackers to execute arbitrary code or cause a denial of service that is memory corruption and application crash through a crafted HTML document.

Impact:

By this type of vulnerability, information can be unveiled and changes can be made without any authorization. Also, a service can be broken up.

Solution:

As often, in most cases like this, we recommend users to upgrade to the latest version of the software product (Apple Safari version 4).

References:http://www.vupen.com/english/advisories/2009/1522
http://support.apple.com/kb/HT3613
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
http://www.securityfocus.com/bid/35260
http://securitytracker.com/id?1022345
http://secunia.com/advisories/35379

Impact

CVSS Severity

CVSS Version 2 Metrics:

CVSS v2 Base Score:9.3 (HIGH)Access Vector:N/A
Impact Subscore: 10.0Access Complexity: Medium
Exploitability Subscore: 8.6Authentication: Not required to exploit
Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service

Say something interesting!

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Latest Comments

July 31, 2010
http://arthriti .. me-breasts.htmlprime breasts, jnin, http://rentacar .. ssing-tube.htmlpissing tube,... more..
July 31, 2010
http://usa-batt .. er-preview.htmlcorbin fisher preview, :PP, http://sahanav. .. e-magazine.htmlelle... more..
July 31, 2010
http://mj-shawb .. -incubator.htmlegg incubator, 8-O, http://hemetmar .. /rod-laver.htmlrod laver,... more..
more comments..
rss
Home > Vulnerabilities > pc1-2009-1555