CERT-In Vulnerability Note
CIVN-2014-0286
Multiple Vulnerabilities in Apple Safari
Original Issue Date:December 18, 2014
Severity Rating: MEDIUM
Software Affected
- Apple Safari 8.0.1
- Apple Safari 7.1.1
- Apple Safari 6.2.1
Overview
Multiple vulnerabilities have been reported in Apple safari which could allow unauthenticated remote attackers to spoof the user interface (UI), execute arbitrary code, or cause a denial-of-service (DoS) condition on the system installed with affected version of software.
Description
These vulnerabilities are caused due to UI spoofing and memory corruption errors in the WebKit component of Apple Safari. A remote attacker could exploit these vulnerabilities by enticing users to open a specially crafted malicious link.
Successful exploitation of these vulnerabilities could allow the attacker to spoof the UI, trigger a memory corruption error that could be used to execute arbitrary code or cause an unexpected termination of the affected browser leads to Denial-Of-Service (DoS) conditions.
Solution
Apply appropriate patches as mentioned in
Apple Security Updates
Vendor Information
Apple
http://support.apple.com/en-in/HT6596
References
Security tracker
http://securitytracker.com/id/1031296
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36642
Securityfocus
http://www.securityfocus.com/archive/1/534148
http://www.securityfocus.com/bid/71137
http://www.securityfocus.com/bid/71144
http://www.securityfocus.com/bid/71439
http://www.securityfocus.com/bid/71445
http://www.securityfocus.com/bid/71459/
http://www.securityfocus.com/bid/71461/
http://www.securityfocus.com/bid/71462
http://www.securityfocus.com/bid/71438
http://www.securityfocus.com/bid/71442
http://www.securityfocus.com/bid/71444
http://www.securityfocus.com/bid/71449
http://www.securityfocus.com/bid/71451
CVE Name
CVE-2014-4452
CVE-2014-4459
CVE-2014-4465
CVE-2014-4466
CVE-2014-4468
CVE-2014-4469
CVE-2014-4470
CVE-2014-4471
CVE-2014-4472
CVE-2014-4473
CVE-2014-4474
CVE-2014-4475
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|