Site Network: Beskerming.com | Skiifwrald.com | Jongsma & Jongsma

Security for All

Sûnnet Beskerming is a company with a focus and a drive to provide Information Security services for all those who want to stay safe and secure in an online world.

Username: | Password: Contact us to request an account

Safari - Remote hacker automatic control

Version: 3.0
Technical Details:

Adding a page with a title tag in excess of 1024 bytes to a user's bookmarks can lead to arbitrary code execution on the Windows Safari 3 Beta. Successful exploitation of this vulnerability has been achieved, with exploit samples circulated amongst a small group of recipients.

Description:

Another vulnerability affecting the Safari 3 Beta release on Windows has been discovered. In this particular vulnerability, adding a page with an exceedingly long title to a user's bookmarks can lead to the remote attacker possibly gaining control over the victim's system.

Although exploit code does exist, it has only been made available to a small group of recipients.

Mitigation:

Consider the use of an alternate browser until Apple is able to release a patch to address the vulnerability.

Updates:

Not Yet Available

Source:

http://www.frsirt.com/english/advisories/2007/2340

Exploits:

http://www.frsirt.com/english/services/

External Tracking Data:

Not Yet Identified


Social bookmark this page