Breaking News

Z890 AORUS TACHYON ICE Dominates Global DDR5 Performance, Shattering World Record at DDR5-13530 New Vero L6 generation of the PSUs The Lockerstor Gen2 Series Brings 10-Gigabit Performance for 5-Gigabit Prices ASUS Republic of Gamers Launches ROG Matrix GeForce RTX 5090 Razer Unveils Raiju V3 Pro Elite Esports Controller For PS 5

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Reveal Important Safari Vulnerability

Researchers Reveal Important Safari Vulnerability

Enterprise & IT May 11,2010 0

Danish vulnerability tracker Secunia found a vulnerability and a security issue in Apple's Safari browser. According to Secunia, the security issue can lead to exposure of sensitive information and the vulnerability can be exploited by malicious people to compromise a user's system.

An error in the handling of parent windows can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows, Secunia announced.

The security issue is caused due to Safari including HTTP basic authentication credentials in an HTTP request if a web page that requires HTTP basic authentication redirects to a different domain (e.g. via a "Location" header).

The vulnerability and the security issue are confirmed in Safari version 4.0.5 for Windows.

The company recommends users not to visit untrusted web sites or follow links from untrusted sources. In addition, users should not authenticate to sites that use HTTP basic authentication and use redirections to different domains.

US-CERT also confirmed the vulnerability affecting Apple Safari.

"By convincing a user to open a specially crafted web page, an attacker may be able to execute arbitrary code. Exploit code for this vulnerability is publicly available," US-CERT said.

US-CERT encourages users and administrators to disable JavaScript until a fix is provided by Apple.

Tags: safariApple
Previous Post
Sharp Develops 3D Camera Module for Mobile Devices Capable of Capturing HD 3D Video
Next Post
Report: $51 Billion Lost to Software Piracy in 2009

Related Posts

  • Apple introduces Digital ID

  • Apple unleashes M5 CPU and new devices

  • Apple debuts iPhone 17, Pro, Max, Air, Watch Series 11, Watch Ultra 3, Watch SE 3, AirPods Pro 3

  • Apple unveils Mac Studio featuring M4 Max and new M3 Ultra

  • Apple introduces iPad Air with powerful M3 chip and new Magic Keyboard

  • Apple debuts iPhone 16e

  • Apple introduces M4 Pro and M4 Max and new MacBook Pro

  • Apple unveils the new iMac with M4, supercharged by Apple Intelligence and available in fresh colors

Latest News

Z890 AORUS TACHYON ICE Dominates Global DDR5 Performance, Shattering World Record at DDR5-13530
PC components

Z890 AORUS TACHYON ICE Dominates Global DDR5 Performance, Shattering World Record at DDR5-13530

New Vero L6 generation of the PSUs
PC components

New Vero L6 generation of the PSUs

The Lockerstor Gen2 Series Brings 10-Gigabit Performance for 5-Gigabit Prices
Enterprise & IT

The Lockerstor Gen2 Series Brings 10-Gigabit Performance for 5-Gigabit Prices

ASUS Republic of Gamers Launches ROG Matrix GeForce RTX 5090
GPUs

ASUS Republic of Gamers Launches ROG Matrix GeForce RTX 5090

Razer Unveils Raiju V3 Pro Elite Esports Controller For PS 5
Gaming

Razer Unveils Raiju V3 Pro Elite Esports Controller For PS 5

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed