Vulnerabilities > CVE-2008-0035 - Resource Management Errors vulnerability in Apple Safari

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
apple
CWE-399
nessus

Summary

Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_10_5_2.NASL
    descriptionThe remote host is running a version of Mac OS X 10.5.x that is prior to 10.5.2. Mac OS X 10.5.2 contains several security fixes for a number of programs.
    last seen2020-06-01
    modified2020-06-02
    plugin id30255
    published2008-02-12
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/30255
    titleMac OS X 10.5.x < 10.5.2 Multiple Vulnerabilities
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_SECUPD2008-001.NASL
    descriptionThe remote host is running a version of Mac OS X 10.4 that does not have the security update 2008-001 applied. This update contains several security fixes for a number of programs.
    last seen2020-06-01
    modified2020-06-02
    plugin id30254
    published2008-02-12
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/30254
    titleMac OS X Multiple Vulnerabilities (Security Update 2008-001)

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 27296 CVE(CAN) ID: CVE-2008-0035 iPod touch(也被称为iTouch)是苹果公司发布的MP4播放器,iPhone是其发布的智能手机。 iPhone和iPod Touch所内嵌的Safari浏览器处理畸形URL时存在漏洞,远程攻击者可能利用此漏洞控制用户系统。 Safari浏览器没有正确地处理URL中的Foundation参数,如果用户受骗跟随了恶意链接的话,就可能触发内存破坏,导致浏览器崩溃或执行任意指令。 Apple iPhone 1.0 - 1.1.2 Apple iTouch 1.1 - 1.1.2 Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17381&cat=1&platform=osx&method=sa/SecUpd2008-001PPC.dmg target=_blank>http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17381&cat=1&platform=osx&method=sa/SecUpd2008-001PPC.dmg</a> <a href=http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17382&cat=57&platform=osx&method=sa/SecUpd2008-001Univ.dmg target=_blank>http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17382&cat=57&platform=osx&method=sa/SecUpd2008-001Univ.dmg</a>
idSSV:2915
last seen2017-11-19
modified2008-02-21
published2008-02-21
reporterRoot
titleApple iPhone和iPod Touch Foundation参数内存破坏漏洞