Breaking News

Sony Unveils Sony FE 100mm F2.8 Macro GM OSS Creative Launches Aurvana Ace 3 GIGABYTE Announces Availability of 27” QHD 280Hz WOLED Gaming Monitor MO27Q28G with 4-Sided Borderless Design Crucial ® LPCAMM2 Powers AI-Ready Laptops With Breakthrough 8,533MT/s Speeds Logitech announces MX Master 4

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Reveal Important Safari Vulnerability

Researchers Reveal Important Safari Vulnerability

Enterprise & IT May 11,2010 0

Danish vulnerability tracker Secunia found a vulnerability and a security issue in Apple's Safari browser. According to Secunia, the security issue can lead to exposure of sensitive information and the vulnerability can be exploited by malicious people to compromise a user's system.

An error in the handling of parent windows can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows, Secunia announced.

The security issue is caused due to Safari including HTTP basic authentication credentials in an HTTP request if a web page that requires HTTP basic authentication redirects to a different domain (e.g. via a "Location" header).

The vulnerability and the security issue are confirmed in Safari version 4.0.5 for Windows.

The company recommends users not to visit untrusted web sites or follow links from untrusted sources. In addition, users should not authenticate to sites that use HTTP basic authentication and use redirections to different domains.

US-CERT also confirmed the vulnerability affecting Apple Safari.

"By convincing a user to open a specially crafted web page, an attacker may be able to execute arbitrary code. Exploit code for this vulnerability is publicly available," US-CERT said.

US-CERT encourages users and administrators to disable JavaScript until a fix is provided by Apple.

Tags: safariApple
Previous Post
Sharp Develops 3D Camera Module for Mobile Devices Capable of Capturing HD 3D Video
Next Post
Report: $51 Billion Lost to Software Piracy in 2009

Related Posts

  • Apple debuts iPhone 17, Pro, Max, Air, Watch Series 11, Watch Ultra 3, Watch SE 3, AirPods Pro 3

  • Apple unveils Mac Studio featuring M4 Max and new M3 Ultra

  • Apple introduces iPad Air with powerful M3 chip and new Magic Keyboard

  • Apple debuts iPhone 16e

  • Apple introduces M4 Pro and M4 Max and new MacBook Pro

  • Apple unveils the new iMac with M4, supercharged by Apple Intelligence and available in fresh colors

  • Apple introduces powerful new iPad mini built for Apple Intelligence

  • Apple expands Self Service Repair Diagnostics support to Europe

Latest News

Sony Unveils Sony FE 100mm F2.8 Macro GM OSS
Cameras

Sony Unveils Sony FE 100mm F2.8 Macro GM OSS

Creative Launches Aurvana Ace 3
Consumer Electronics

Creative Launches Aurvana Ace 3

GIGABYTE Announces Availability of 27” QHD 280Hz WOLED Gaming Monitor MO27Q28G with 4-Sided Borderless Design
Gaming

GIGABYTE Announces Availability of 27” QHD 280Hz WOLED Gaming Monitor MO27Q28G with 4-Sided Borderless Design

Crucial ® LPCAMM2 Powers AI-Ready Laptops With Breakthrough 8,533MT/s Speeds
Enterprise & IT

Crucial ® LPCAMM2 Powers AI-Ready Laptops With Breakthrough 8,533MT/s Speeds

Logitech announces MX Master 4
Enterprise & IT

Logitech announces MX Master 4

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed