Affected Versions:
Apple Safari 5. xApple Safari 4.x
Vulnerability description:
Bugtraq id: 42037CVE ID: CVE-2010-1785Safari is the default WEB browser bundled in the Apple family machine operating system. Safari Webkit does not correctly implement the first-letter style in the context of SVG text elements,
When applying the style to this element, the height is calculated first to determine the inline box overflow. When traversing a height element,
The function library uses data from a linebox that does not exist. Successful attacks may cause arbitrary code execution.
<* Reference
Wushi (
Wooshi@gmail.com)
Http://marc.info /? L = bugtraq & m = 128110471425043 & w = 2
Http://support.apple.com/kb/HT4276
*>SEBUG Security suggestion: vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apple.com/safari/download/