MAAS History
Archives
« APPLE-SA-2010-05-18-2 Java for Mac OS X 10.5 Update 7 | Main | Opera Releases 10.53 »
Monday
May102010

Critical Windows Safari Flaw Currently Does Not Affect OSX

There is a critical flaw that is being reported in the Window's version of Safari that can be trigged by a invalid pointer function call. For the flaw to be affective POPUP blocker has to be disabled, currently Safari install with POPUP blocker enabled. In addition based on the code posted I was unable to cause either an application DOS or arbitary code execution. The affect cause a popup window to open with a large String ('AAA...'), you will not see the OK and Cancel button since they are at the very end of the long String. Hitting return will clear the window, our payload would not execute using the latest MacOSX OS and Safari.  

Comments from the proof of concept code indicates platform tested, os+local and credit tag.

  • Bug discovered by Krystian Kloskowski
  • Tested on: Apple Safari 4.0.5 / XP SP2 Polish
  • Shellcode: Windows Execute Command (calc)//* Our version osx/x86/exec - 44 bytes (BLOCK BOX)
  • Local: Yes
  • Remote: Yes (POPUP must be enabled [Ctrl+Shift+K])

 

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (1)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.
Member Account Required
You must have a member account on this website in order to post comments. Log in to your account to enable posting.