Overview
The Apple Webkit contains a memory corruption vulnerability.This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code.
Description
According to Apple: This vulnerability may affect any software that uses the Apple WebKit, including the Safari web browser. Note that this vulnerability is reported to affect software on both the Windows and Apple OS X operating systems. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code. |
Solution
Apply Apple Updates |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://docs.info.apple.com/article.html?artnum=305759
- http://developer.apple.com/opensource/internet/webkit.html
- http://webkit.opendarwin.org/
- http://lists.apple.com/archives/security-announce/2007/Jun/msg00004.html
- http://secunia.com/advisories/25786/
- http://docs.info.apple.com/article.html?artnum=306173
- http://secunia.com/advisories/26287/
Acknowledgements
This vulnerability was reported in Apple Security Update 2007-006. Apple credits Rhys Kidd of Westnet with providing information about this vulnerability.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2007-2399 |
Severity Metric: | 2.55 |
Date Public: | 2007-06-22 |
Date First Published: | 2007-06-22 |
Date Last Updated: | 2008-06-04 21:42 UTC |
Document Revision: | 26 |