Overview
A vulnerability in Apple Mac OS X WebKit may allow an attacker to execute arbitrary code on an affected system.
Description
WebKit From the OpenDarwin WebKit project description, |
Impact
By convincing a user to view a specially crafted web page or HTML file, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user or crash the program that opened the malicious document. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Apple Product Security for reporting this vulnerability. Apple in turn thanks Jesse Ruderman of the Mozilla Corporation.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-3505 |
Severity Metric: | 1.64 |
Date Public: | 2006-08-01 |
Date First Published: | 2006-08-02 |
Date Last Updated: | 2006-08-02 18:10 UTC |
Document Revision: | 32 |