Vulnerabilities > CVE-2008-1024 - Resource Management Errors vulnerability in Apple Safari 3/3.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 | |
Application | 2 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | SAFARI_3_1_1.NASL |
description | The version of Safari installed on the remote host reportedly is affected by several issues : - A malicious website can spoof window titles and URL bars (CVE-2007-2398). - A memory corruption issue in the file downloading capability could lead to a crash or arbitrary code execution (CVE-2008-1024). - A cross-site scripting vulnerability exists in WebKit |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31993 |
published | 2008-04-18 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/31993 |
title | Safari < 3.1.1 Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 28813,28814,28815 CVE(CAN) ID: CVE-2008-1024,CVE-2008-1025,CVE-2008-1026 Safari是苹果家族操作系统默认所捆绑的WEB浏览器。 Safari实现上存在各种漏洞,远程攻击者可能利用这些漏洞控制用户系统。 如果用户使用Safari下载了带有特制名称的文件的话,就可能触发内存破坏,导致浏览器终止或执行任意指令。 Safari的WebKi没有正确地处理主机名中包含有冒号的URL,如果用户受骗打开特制的URL就会导致执行跨站脚本。 WebKit中的正则表达式编译器(JavaScriptCore/pcre/pcre_compile.cpp)中存在堆溢出漏洞。如果在正则表达式中嵌套了大量反复的话,就可以触发这个溢出,导致执行任意指令。 Apple Safari 3.1 Apple Safari 3 Robert Swiecki (<a href=mailto:[email protected] target=_blank>[email protected]</a>) Charlie Miller 链接:<a href=http://support.apple.com/kb/HT1467 target=_blank>http://support.apple.com/kb/HT1467</a> <a href=http://marc.info/?l=bugtraq&m=120838537332599&w=2 target=_blank>http://marc.info/?l=bugtraq&m=120838537332599&w=2</a> |
id | SSV:3186 |
last seen | 2017-11-19 |
modified | 2008-04-18 |
published | 2008-04-18 |
reporter | Root |
title | Apple Safari 3.1.1版本修复多个安全漏洞 |
References
- http://support.apple.com/kb/HT1467
- http://lists.apple.com/archives/security-announce/2008/Apr/msg00001.html
- http://www.kb.cert.org/vuls/id/529441
- http://www.securityfocus.com/bid/28813
- http://www.securitytracker.com/id?1019868
- http://www.vupen.com/english/advisories/2008/0979/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41864