Release date:
Updated on: 2011-12-07
Affected Systems:
Apple Safari 5.x
Apple Safari 4.x
Apple Television 4.3
Apple Television 4.2
Apple Television 4.1
Apple Television 4.0
Apple Television 2.1
Apple Television 1.0
Apple iOS 4.x
Unaffected system:
Apple Safari 5.1 for Windows
Apple Safari 5.1
Apple Safari 5.0.6 for windows
Apple Safari 5.0.6
Apple Television 4.4
Apple iOS 5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48832
Cve id: CVE-2011-0216
Safari is the browser in Mac OS X, the latest operating system of Apple Computer. It uses KDE's KHTML as the core of browser computing.
A single-byte overflow vulnerability exists in the implementation of libxml in Safari versions earlier than 5.0.6. Attackers can exploit this vulnerability to execute arbitrary code or cause a denial of service in affected applications.
<* Source: Billy Rios
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.apple.com/