|
|
|
|
| |
Credit:
The information has been provided by The Zero Day Initiative (ZDI).
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-08-022
|
| |
Vulnerable Systems:
* Safari version 3.1
The specific flaw exists in the regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in WebKit. When nesting regular expressions with large repetitions, a heap overflow occurs resulting in a condition allowing the execution of arbitrary code.
Impact:
Viewing a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution.
CVE Information:
CVE-2008-1026
Vendor Response:
Apple has issued an update to correct this vulnerability. More details can be found at: http://support.apple.com/kb/HT1467
Disclosure Timeline:
2008-03-27 - Vulnerability reported to vendor
2008-04-16 - Coordinated public release of advisory
|
|
|
|
|