SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Browser)  >   Apple Safari Vendors:   Apple Computer
Apple Safari Bugs Let Remote Users Execute Arbitrary Code, Spoof the URL Address Bar, Conduct Cross-Site Scripting Attacks, and Obtain Potentially Sensitive Information
SecurityTracker Alert ID:  1027307
SecurityTracker URL:  http://securitytracker.com/id/1027307
CVE Reference:   CVE-2011-3016, CVE-2011-3021, CVE-2011-3027, CVE-2011-3913, CVE-2012-0678, CVE-2012-0679, CVE-2012-0680, CVE-2012-0682, CVE-2012-0683, CVE-2012-1520, CVE-2012-2815, CVE-2012-3589, CVE-2012-3590, CVE-2012-3591, CVE-2012-3592, CVE-2012-3593, CVE-2012-3594, CVE-2012-3595, CVE-2012-3596, CVE-2012-3597, CVE-2012-3599, CVE-2012-3600, CVE-2012-3603, CVE-2012-3604, CVE-2012-3605, CVE-2012-3608, CVE-2012-3609, CVE-2012-3610, CVE-2012-3611, CVE-2012-3615, CVE-2012-3618, CVE-2012-3620, CVE-2012-3625, CVE-2012-3626, CVE-2012-3627, CVE-2012-3628, CVE-2012-3629, CVE-2012-3630, CVE-2012-3631, CVE-2012-3633, CVE-2012-3634, CVE-2012-3635, CVE-2012-3636, CVE-2012-3637, CVE-2012-3638, CVE-2012-3639, CVE-2012-3640, CVE-2012-3641, CVE-2012-3642, CVE-2012-3644, CVE-2012-3645, CVE-2012-3646, CVE-2012-3650, CVE-2012-3653, CVE-2012-3655, CVE-2012-3656, CVE-2012-3661, CVE-2012-3663, CVE-2012-3664, CVE-2012-3665, CVE-2012-3666, CVE-2012-3667, CVE-2012-3668, CVE-2012-3669, CVE-2012-3670, CVE-2012-3674, CVE-2012-3678, CVE-2012-3679, CVE-2012-3680, CVE-2012-3681, CVE-2012-3682, CVE-2012-3683, CVE-2012-3686, CVE-2012-3689, CVE-2012-3690, CVE-2012-3691, CVE-2012-3693, CVE-2012-3694, CVE-2012-3695, CVE-2012-3696, CVE-2012-3697   (Links to External Site)
Date:  Jul 26 2012
Impact:   Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 6.0
Description:   Multiple vulnerabilities were reported in Apple Safari. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can conduct cross-site scripting attacks. A remote user can conduct HTTP response splitting attacks. A remote user can spoof URLs. A remote user can obtain potentially sensitive information.

A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system [CVE-2011-3016, CVE-2011-3021, CVE-2011-3027, CVE-2011-3913, CVE-2012-0682, CVE-2012-0683, CVE-2012-1520, CVE-2012-3589, CVE-2012-3590, CVE-2012-3591, CVE-2012-3592, CVE-2012-3593, CVE-2012-3594, CVE-2012-3595,
CVE-2012-3596, CVE-2012-3597, CVE-2012-3599, CVE-2012-3600, CVE-2012-3603, CVE-2012-3604, CVE-2012-3605, CVE-2012-3608, CVE-2012-3609, CVE-2012-3610, CVE-2012-3611, CVE-2012-3615, CVE-2012-3618, CVE-2012-3620, CVE-2012-3625,
CVE-2012-3626, CVE-2012-3627, CVE-2012-3628, CVE-2012-3629, CVE-2012-3630, CVE-2012-3631, CVE-2012-3633, CVE-2012-3634, CVE-2012-3635, CVE-2012-3636, CVE-2012-3637, CVE-2012-3638, CVE-2012-3639, CVE-2012-3640, CVE-2012-3641,
CVE-2012-3642, CVE-2012-3644, CVE-2012-3645, CVE-2012-3646, CVE-2012-3653, CVE-2012-3655, CVE-2012-3656, CVE-2012-3661, CVE-2012-3663, CVE-2012-3664, CVE-2012-3665, CVE-2012-3666, CVE-2012-3667, CVE-2012-3668, CVE-2012-3669,
CVE-2012-3670, CVE-2012-3674, CVE-2012-3678, CVE-2012-3679, CVE-2012-3680, CVE-2012-3681, CVE-2012-3682, CVE-2012-3683, CVE-2012-3686] . The code will run with the privileges of the target user.

A remote user can cause arbitrary scripting code to be executed by the target user's browser [CVE-2012-0678, CVE-2012-2815, CVE-2012-3695]. The code will run in the security context of an arbitrary site. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

A remote user can create specially crafted HTML that, when loaded by the target user, will cause files on the target user's system to be sent to a remote server [CVE-2012-0679].

Some password input elements may be autocompleted even if the site specifies that autocomplete be disabled [CVE-2012-0680].

A remote user can create specially crafted HTML that, when loaded by the target user, will exploit a flaw in processing SVG images to obtain memory contents [CVE-2012-3650].

When the target user drags and drops selected text on a specially crafted web page, the web page can obtain information from other domains [CVE-2012-3689] or files from the target user's system [CVE-2012-3690].

A remote user can submit a specially crafted URL to cause the target server to return a split response [CVE-2012-3696]. A remote user can exploit this to spoof content on the target server, attempt to poison any intermediate web caches, or conduct cross-site scripting attacks.

A remote user can create specially crafted HTML that, when loaded by the target user, will exploit a flaw in the processing of CSS property values to obtain information from a different site [CVE-2012-3691].

A remote user can create a URL with specially crafted characters to spoof a domain name in the address bar [CVE-2012-3693].

A user can drag and drop a file to Safari to cause the filesystem path to be disclosed to remote users [CVE-2012-3694].

An application can exploit an access control flaw to escape the sandbox and access files with the privileges of the target user [CVE-2012-3697].

miaubiz, Arthur Gerkis, Masato Kinugawa, Aaron Sigel of vtty.com, Dan Poltawski of Moodle, Apple Product Security, Dave Mandelin of Mozilla, Martin Barbella of the Google Chrome Security Team, Jose A. Vazquez of spa-s3c.blogspot.com (via iDefense VCP), Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt, and Dan Boneh of the Stanford University Security Laboratory, Skylined of the Google Chrome Security Team, Abhishek Arya of Google Chrome Security Team, David Levin of the Chromium development community, Cris Neckar of the Google Chrome Security team, Stephen Chenney of the Chromium development community, Slawomir Blazek, Julien Chaffraix of the Chromium development community, Thomas Sepez of the Chromium development community, Trevor Squires of propaneapp.com, Chris Leary of Mozilla, Adam Barth of the Google Chrome Security Team, wushi of team509 (via iDefense VCP), Robin Cao of Torch Mobile (Beijing), David Bloom of Cue, Matt Cooley of Symantec, Daniel Cheng of Google, Masato Kinugawa, and David Belcher of the BlackBerry Security Incident Response Team reported these vulnerabilities.

Impact:   A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can access the target user's cookies (including authentication cookies), if any, associated with an arbitrary site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

A remote user can create a URL that, when loaded by the target user, will cause arbitrary content to be displayed.

A remote user may be able to poison any intermediate web caches with arbitrary content.

A remote user can obtain potentially sensitive information.

Solution:   The vendor has issued a fix (6.0), available via the Apple Software Update application.

The vendor's advisory is available at:

http://support.apple.com/kb/HT5400

Vendor URL:  support.apple.com/kb/HT5400 (Links to External Site)
Cause:   Access control error, Boundary error, Input validation error
Underlying OS:   UNIX (OS X)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Sep 13 2012 (Apple Issues Fix for iTunes) Apple Safari Bugs Let Remote Users Execute Arbitrary Code, Spoof the URL Address Bar, Conduct Cross-Site Scripting Attacks, and Obtain Potentially Sensitive Information
Apple has issued a fix for iTunes for Windows.
Sep 26 2012 (Apple Issues Fix for Apple TV) Apple Safari Bugs Let Remote Users Execute Arbitrary Code, Spoof the URL Address Bar, Conduct Cross-Site Scripting Attacks, and Obtain Potentially Sensitive Information
Apple has issued a fix for Apple TV.



 Source Message Contents

Date:  Thu, 26 Jul 2012 06:54:56 +0000
Subject:  Apple Safari


Excerpt from APPLE-SA-2012-07-25-1 Safari 6.0

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  Multiple memory corruption issues existed in WebKit.
These issues are addressed through improved memory handling.
CVE-ID
CVE-2011-3016 : miaubiz
CVE-2011-3021 : Arthur Gerkis
CVE-2011-3027 : miaubiz
CVE-2011-3913 : Arthur Gerkis

Safari
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to a cross-
site scripting attack
Description:  A cross-site scripting issue existed in the handling of
feed:// URLs. This update removes handling of feed:// URLs.
CVE-ID
CVE-2012-0678 : Masato Kinugawa

Safari
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may cause files from
the user's system to be sent to a remote server
Description:  An access control issue existed in the handling of
feed:// URLs. This update removes handling of feed:// URLs.
CVE-ID
CVE-2012-0679 : Aaron Sigel of vtty.com

Safari
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Passwords may autocomplete even when the site specifies that
autocomplete should be disabled
Description:  Password input elements with the autocomplete attribute
set to "off" were being autocompleted. This update addresses the
issue by improved handling of the autocomplete attribute.
CVE-ID
CVE-2012-0680 : Dan Poltawski of Moodle

CVE-2012-0682 : Apple Product Security
CVE-2012-0683 : Dave Mandelin of Mozilla
CVE-2012-1520 : Martin Barbella of the Google Chrome Security Team
using AddressSanitizer, Jose A. Vazquez of spa-s3c.blogspot.com
working with iDefense VCP

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to a cross-
site disclosure of information
Description:  A cross-origin issue existed in the handling of iframes
and fragment identifiers. This issue is addressed through improved
origin tracking.
CVE-ID
CVE-2012-2815 : Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt,
and Dan Boneh of the Stanford University Security Laboratory

CVE-2012-3589 : Dave Mandelin of Mozilla
CVE-2012-3590 : Apple Product Security
CVE-2012-3591 : Apple Product Security
CVE-2012-3592 : Apple Product Security
CVE-2012-3593 : Apple Product Security
CVE-2012-3594 : miaubiz
CVE-2012-3595 : Martin Barbella of Google Chrome Security
CVE-2012-3596 : Skylined of the Google Chrome Security Team
CVE-2012-3597 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3599 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3600 : David Levin of the Chromium development community
CVE-2012-3603 : Apple Product Security
CVE-2012-3604 : Skylined of the Google Chrome Security Team
CVE-2012-3605 : Cris Neckar of the Google Chrome Security team
CVE-2012-3608 : Skylined of the Google Chrome Security Team
CVE-2012-3609 : Skylined of the Google Chrome Security Team
CVE-2012-3610 : Skylined of the Google Chrome Security Team
CVE-2012-3611 : Apple Product Security
CVE-2012-3615 : Stephen Chenney of the Chromium development community
CVE-2012-3618 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3620 : Abhishek Arya of Google Chrome Security Team
CVE-2012-3625 : Skylined of Google Chrome Security Team
CVE-2012-3626 : Apple Product Security
CVE-2012-3627 : Skylined and Abhishek Arya of Google Chrome Security
team
CVE-2012-3628 : Apple Product Security
CVE-2012-3629 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3630 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3631 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3633 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3634 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3635 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3636 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3637 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3638 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3639 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3640 : miaubiz
CVE-2012-3641 : Slawomir Blazek
CVE-2012-3642 : miaubiz
CVE-2012-3644 : miaubiz
CVE-2012-3645 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3646 : Julien Chaffraix of the Chromium development
community, Martin Barbella of Google Chrome Security Team using
AddressSanitizer


WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to the
disclosure of the disclosure of memory contents
Description:  An uninitialized memory access issue existed in the
handling of SVG images. This issue is addressed through improved
memory initialization.
CVE-ID
CVE-2012-3650 : Apple


CVE-2012-3653 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3655 : Skylined of the Google Chrome Security Team
CVE-2012-3656 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3661 : Apple Product Security
CVE-2012-3663 : Skylined of Google Chrome Security Team
CVE-2012-3664 : Thomas Sepez of the Chromium development community
CVE-2012-3665 : Martin Barbella of Google Chrome Security Team using
AddressSanitizer
CVE-2012-3666 : Apple
CVE-2012-3667 : Trevor Squires of propaneapp.com
CVE-2012-3668 : Apple Product Security
CVE-2012-3669 : Apple Product Security
CVE-2012-3670 : Abhishek Arya of Google Chrome Security Team using
AddressSanitizer, Arthur Gerkis
CVE-2012-3674 : Skylined of Google Chrome Security Team
CVE-2012-3678 : Apple Product Security
CVE-2012-3679 : Chris Leary of Mozilla
CVE-2012-3680 : Skylined of Google Chrome Security Team
CVE-2012-3681 : Apple
CVE-2012-3682 : Adam Barth of the Google Chrome Security Team
CVE-2012-3683 : wushi of team509 working with iDefense VCP
CVE-2012-3686 : Robin Cao of Torch Mobile (Beijing)

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Dragging and dropping selected text on a web page may lead
to a cross-site information disclosure
Description:  A cross-origin issue existed in the handling of drag
and drop events. This issue is addressed through improved origin
tracking.
CVE-ID
CVE-2012-3689 : David Bloom of Cue

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Dragging and dropping selected text on a web page may cause
files from the user's system to be sent to a remote server
Description:  An access control issue existed in the handling of drag
and drop events. This issue is addressed through improved origin
tracking.
CVE-ID
CVE-2012-3690 : David Bloom of Cue

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to a cross-
site disclosure of information
Description:  A cross-origin issue existed in the handling of CSS
property values. This issue is addressed through improved origin
tracking.
CVE-ID
CVE-2012-3691 : Apple

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Look-alike characters in a URL could be used to masquerade a
website
Description:  The International Domain Name (IDN) support and Unicode
fonts embedded in Safari could have been used to create a URL which
contains look-alike characters. These could have been used in a
malicious website to direct the user to a spoofed site that visually
appears to be a legitimate domain. This issue is addressed by
supplementing WebKit's list of known look-alike characters. Look-
alike characters are rendered in Punycode in the address bar.
CVE-ID
CVE-2012-3693 : Matt Cooley of Symantec

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Dragging and dropping a file to Safari may reveal the
filesystem path of the file to the website
Description:  An information disclosure issue existed in the handling
of dragged files. This issue is addressed through improved handling
of dragged files.
CVE-ID
CVE-2012-3694 : Daniel Cheng of Google, Aaron Sigel of vtty.com

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to a cross-
site scripting attack
Description:  A canonicalization issue existed in the handling of
URLs. This may have led to cross-site scripting on sites which use
the location.href property. This issue is addressed through improved
canonicalization of URLs.
CVE-ID
CVE-2012-3695 : Masato Kinugawa

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  Visiting a maliciously crafted website may lead to HTTP
request splitting
Description:  An HTTP header injection issue existed in the handling
of WebSockets. This issue is addressed through improved WebSockets
URI sanitization.
CVE-ID
CVE-2012-3696 : David Belcher of the BlackBerry Security Incident
Response Team

WebKit
Available for:  OS X Lion v10.7.4, OS X Lion Server v10.7.4
Impact:  An attacker may be able to escape the sandbox and access any
file the current user has access to
Description:  An access control issue existed in the handling of file
URLs. An attacker who gains arbitrary code execution in a Safari
WebProcess may be able to bypass the sandbox and access any file that
the user running Safari has access to. This issue is addressed
through improved handling of file URLs.
CVE-ID
CVE-2012-3697 : Aaron Sigel of vtty.com




 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC