Breaking News

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio Creative Announces Sound Blaster AE-X Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Reveal Important Safari Vulnerability

Researchers Reveal Important Safari Vulnerability

Enterprise & IT May 11,2010 0

Danish vulnerability tracker Secunia found a vulnerability and a security issue in Apple's Safari browser. According to Secunia, the security issue can lead to exposure of sensitive information and the vulnerability can be exploited by malicious people to compromise a user's system.

An error in the handling of parent windows can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows, Secunia announced.

The security issue is caused due to Safari including HTTP basic authentication credentials in an HTTP request if a web page that requires HTTP basic authentication redirects to a different domain (e.g. via a "Location" header).

The vulnerability and the security issue are confirmed in Safari version 4.0.5 for Windows.

The company recommends users not to visit untrusted web sites or follow links from untrusted sources. In addition, users should not authenticate to sites that use HTTP basic authentication and use redirections to different domains.

US-CERT also confirmed the vulnerability affecting Apple Safari.

"By convincing a user to open a specially crafted web page, an attacker may be able to execute arbitrary code. Exploit code for this vulnerability is publicly available," US-CERT said.

US-CERT encourages users and administrators to disable JavaScript until a fix is provided by Apple.

Tags: safariApple
Previous Post
Sharp Develops 3D Camera Module for Mobile Devices Capable of Capturing HD 3D Video
Next Post
Report: $51 Billion Lost to Software Piracy in 2009

Related Posts

  • Apple introduces AirPods Max 2

  • Apple introduces the new M5 Pro/Max powered laptops and new Studio Display

  • Apple introduces iPhone 17e and new new iPad Air

  • Apple introduces new AirTag with expanded connectivity range and improved findability

  • Apple introduces Digital ID

  • Apple unleashes M5 CPU and new devices

  • Apple debuts iPhone 17, Pro, Max, Air, Watch Series 11, Watch Ultra 3, Watch SE 3, AirPods Pro 3

  • Apple unveils Mac Studio featuring M4 Max and new M3 Ultra

Latest News

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit
PC components

G.SKILL Showcases DDR5-9200 1.1V 16GBx2 High-Speed CU-DIMM Memory Kit

Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio
Consumer Electronics

Sony Introduces BRAVIA 9 II and BRAVIA 7 II RGB TVs and the BRAVIA Theatre Trio

Creative Announces Sound Blaster AE-X
PC components

Creative Announces Sound Blaster AE-X

Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel
Gaming

Acer Expands Gaming Portfolio With Predator Atlas 8 Handheld Powered by Intel

COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition
GPUs

COLORFUL Presents Limited Edition iGame GeForce RTX 5070 Ultra OC 12GB x 007 First Light Edition

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed