This application requires Javascript for optimal performance.

Apple.Safari.Parent.Close.Use.After.Free.Code.Execution

Release Date

Mar 14, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a code-execution vulnerability in Apple Safari.

The vulnerability is caused by an error when the vulnerable software handles a malicious JavaScript. It allows a remote attacker to execute arbitrary code via sending a crafted web page that entices the user to close some popup windows.

Affected Products

Apple Safari 4.x

Recommended Actions

Do not open untrusted web pages.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-1939

Reference: VID-25679