Release date:
Updated on:
Affected Systems:
Apple Safari <5.1.7
WebKit Open Source Project WebKit 1.2.5
WebKit Open Source Project WebKit 1.2.3
WebKit Open Source Project WebKit 1.2.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54680
Cve id: CVE-2012-0682, CVE-2012-0683, CVE-2012-1520, CVE-2012-3589, CVE-2012-3590, CVE-2012-3591, CVE-2012-3592, CVE-2012-3593, CVE-2012-3594, CVE-2012-3595, CVE-2012-3596, CVE-2012-3597, CVE-2012-3599, CVE-2012-3600, CVE-2012-3603, CVE-2012-3604, CVE-2012-3609, CVE-2012-3610, CVE-2012-3611, CVE-2012-3615, CVE-2012-3618, CVE-2012-3620, CVE-2012-3625, CVE-2012-3626, CVE-2012-3627, CVE-2012-3628, CVE-2012-3629, CVE-2012-3630, CVE-2012-3631, CVE-2012-3633, CVE-2012-3634, CVE-2012-3635, CVE-2012-3636, CVE-2012-3637, CVE-2012-3638, CVE-2012-3640, CVE-2012-3641, CVE-2012-3642, CVE-2012-3644, CVE-2012-3645, CVE-2012-3646, CVE-2012-3653, CVE-2012-3655, CVE-2012-3656, CVE-2012-3661, CVE-2012-3663, CVE-2012-3664, CVE-2012-3665, CVE-2012-3666, CVE-2012-3667, CVE-2012-3668, CVE-2012-3669, CVE-2012-3670, CVE-2012-3674, CVE-2012-3679, CVE-2012-3680, CVE-2012-3681, CVE-2012-3682, CVE-2012-3683, CVE-2012-3686
WebKit is an open-source browser engine with Gecko (the typographical engine used by Mozilla Firefox) and Trident (also known as MSHTML, the typographical engine used by IE ). WebKit is also the name of the Apple Mac OS x System engine Framework version. It is mainly used in Safari, Dashboard, Mail, and other Mac OS X programs.
The WebKit of earlier versions of Apple Safari 6.0 has multiple remote code execution vulnerabilities with unknown details. This vulnerability allows remote attackers to execute man-in-the-middle attacks, resulting in arbitrary code execution.
<* Source: Apple
Dave Mandelin
Martin Barbella
Link: http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.html
Http://support.apple.com/kb/HT5400
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WebKit Open Source Project
--------------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://webkit.org/