|
|
|
|
| |
Credit:
The information has been provided by wushi.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-10-146/
|
| |
Vulnerable Systems:
* Apple Safari
User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the library's support for mouse events on a particular element. If a mouse event is dispatched to an element when one of it's attributes is undefined, the library will dereference a memory pointer pointing to arbitrary data. Usage of this element can then lead to code execution under the context of the application.
Patch Availability:
http://support.apple.com/kb/HT4225
http://support.apple.com/kb/HT4070
CVE Information:
CVE-2010-0048
Disclosure Timeline:
2010-06-01 - Vulnerability reported to vendor
2010-08-09 - Coordinated public release of advisory
|
|
|
|
|