Release date: 2010-07-28
Updated on: 2010-08-09
Affected Systems:
Apple Safari 5.x
Apple Safari 4.x
Unaffected system:
Apple Safari 5.0.1
Apple Safari 4.1.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 42046
Cve id: CVE-2010-1786
Safari is the default WEB browser bound to the operating system of the Apple family.
Safari Webkit has a vulnerability in the layout implementation of special labels used to embed external documents into the SVG namespace. Then, when you try to calculate the layout information used to render the label content, you may access the linebox that has been released, resulting in arbitrary code execution.
<* Source: wushi (wooshi@gmail.com)
Link: http://marc.info /? L = bugtraq & m = 128110426324154 & w = 2
Http://support.apple.com/kb/HT4276
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apple.com/safari/download/