Vulnerabilities > CVE-2010-1385 - Resource Management Errors vulnerability in Apple Safari
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Windows NASL id SAFARI_5_0.NASL description The version of Safari installed on the remote Windows host is earlier than 5.0. As such, it is potentially affected by numerous issues in the following components : - ColorSync - Safari - WebKit last seen 2020-06-01 modified 2020-06-02 plugin id 46838 published 2010-06-08 reporter This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/46838 title Safari < 5.0 Multiple Vulnerabilities NASL family MacOS X Local Security Checks NASL id MACOSX_SAFARI5_0.NASL description The version of Apple Safari installed on the remote Mac OS X host is earlier than 5.0 / 4.1. As such, it is potentially affected by numerous issues in the following components : - Safari - WebKit last seen 2020-06-01 modified 2020-06-02 plugin id 46837 published 2010-06-08 reporter This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/46837 title Mac OS X : Apple Safari < 5.0 / 4.1
Oval
accepted | 2013-12-30T04:01:04.721-05:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||
description | Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document. | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:7199 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2010-06-08T17:30:00.000-05:00 | ||||||||||||||||||||
title | Apple Safari PDF Handling Vulnerability | ||||||||||||||||||||
version | 14 |
References
- http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html
- http://secunia.com/advisories/40105
- http://securitytracker.com/id?1024067
- http://support.apple.com/kb/HT4196
- http://www.securityfocus.com/bid/40620
- http://www.vupen.com/english/advisories/2010/1373
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7199