This application requires Javascript for optimal performance.

Apple.Webkit.SVG.Floating.Text.Element.Code.Execution

Release Date

Sep 02, 2010

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a code-execution vulnerability in Apple Webkit.

This issue is caused by an error when the vulnerable software handles malformed floating elements within an SVG document. It may allow remote attackers to execute arbitrary code by sending a crafted web page.

Affected Products

Safari 4 (Mac OS X 10.4)
Safari 5 (Windows)
Safari 5 (Mac OS X 10.6)
Safari 5 (Mac OS X 10.5)

Recommended Actions

Refer to the vendor's web site for the suggested workaround:
http://support.apple.com/kb/HT4276

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-1787

Reference/s

http://www.zerodayinitiative.com/advisories/ZDI-10-153

Reference: VID-24110