Vulnerability Note VU#176732
Apple Safari vulnerable to buffer overflow
OverviewApple Safari is vulnerable to a stack-based buffer overflow. This may allow a remote attacker to execute arbitrary code on a vulnerable system.
I. DescriptionSafari
Apple Safari is a web browser that comes with the Mac OS X operating system.
The Problem
Apple Safari contains a stack-based buffer overflow. This vulnerability can be triggered by persuading a user to access a web page containing specially crafted JavaScript with Safari.
II. ImpactA remote attacker may be able to execute arbitrary code on a vulnerable system.
III. SolutionInstall an update
This issue is corrected in Apple Security Update 2006-001.
Disable JavaScript in Safari
For instructions on how to disable JavaScript in Safari, please refer to the Safari section of the Securing Your Web Browser document.
Systems Affected
References
http://www.us-cert.gov/reading_room/securing_browser/#Safari
http://docs.info.apple.com/article.html?artnum=303382
http://secunia.com/advisories/19064/
Credit
This issue was reported in Apple Security Update 2006-001.
This document was written by Jeff Gennari
Other Information
| Date Public | 03/02/2006 |
| Date First Published | 03/03/2006 09:51:08 AM |
| Date Last Updated | 03/03/2006 |
| CERT Advisory | |
| CVE Name | CVE-2006-0387 |
| US-CERT Technical Alerts | |
| Metric | 17.21 |
| Document Revision | 10 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|