vendor:
Safari
by:
Jeremy Brown
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Safari
Affected Version From: Safari 3.2.3
Affected Version To: Safari 4.1.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Safari 3.2.3 (Win32) JavaScript ‘eval’ Remote Denial of Service Exploit
Safari crashes when interpreting a webpage that calls the "eval" JavaScript function with "A/" repeating 21526 times (43052 bytes). When triggering this vulnerability, Safari will throw a "Stack Overflow" exception, and then an access violation when adjusting the trigger to "A/" repeating 21697 times (43394 bytes). The problem originates in the module "WebKit.dll". Safari uses this module as part of the WebKit layout engine (www.webkit.org).
Mitigation:
Apple fixed this issue in Safari 4 (4.1.2 tested)