|
|
|
![]() |
Vulnerability Note VU#566132Apple Mac OS X WebKit may allow code execution when visiting a malicious websiteOverviewA vulnerability in Apple Mac OS X WebKit may allow an attacker to execute arbitrary code on an affected system.I. DescriptionWebKitFrom the OpenDarwin WebKit project description,
The Problem Per Apple, an attacker may be able to create a specially crafted HTML document that could cause a previously deallocated object to be accessed. II. ImpactBy convincing a user to view a specially crafted web page or HTML file, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user or crash the program that opened the malicious document.III. SolutionUpgradeApple has addressed this issue in Security Update 2006-004. Refer to Apple's Security Update site for more information.
References
Thanks to Apple Product Security for reporting this vulnerability. Apple in turn thanks Jesse Ruderman of the Mozilla Corporation. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||