vendor:
Safari
by:
Vitaliy Toropov
8,8
CVSS
HIGH
Heap Buffer Overflow
119
CWE
Product Name: Safari
Affected Version From: 6.0.1
Affected Version To: 6.0.1 for iOS 6.0 and OS X 10.7/8, possibly earlier
Patch Exists: YES
Related CWE: CVE-2012-3748
CPE: a:apple:safari
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iOS 6.0 and OS X 10.7/8
2013
Apple Safari Heap Buffer Overflow
A heap buffer overflow vulnerability exists within the WebKit's JavaScriptCore JSArray::sort(...) method. This method accepts a user-defined JavaScript function and can be used to trigger the heap buffer overflow.
Mitigation:
Apple released a patch for this vulnerability on 2012/11/01.