Skip to main content

Apple Safari Memory Corruption and Address Bar Spoofing Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 26 Mar 2008 4427 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Apple Safari for Windows, which could be exploited by remote attackers to spoof arbitrary web sites, cause a denial of service or compromise a vulnerable system.

1. Due to a memory corruption error when handling overly long filenames, which could be exploited by attackers to crash an affected browser or execute arbitrary code by tricking a user into clicking a specially crafted URL (e.g. to download a ZIP archive).

2. Due to an error when handling certain windows, which could be exploited by malicious web sites to conduct phishing attacks.


Impact

  • Remote Code Execution
  • Spoofing

System / Technologies affected

  • Safari for Windows 3.x

Solutions

There is no patch available for this vulnerability currently.

Temporary Solution: Do not browse untrusted web sites.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link