Release date:
Updated on:
Affected Systems:
WebKit Open Source Project WebKit
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67554
CVE (CAN) ID: CVE-2014-1346
WebKit is an open-source browser engine and the name of the Framework Version of Apple Mac OS X System engine.
When WebKit processes unicode characters in a URL, the encoding vulnerability exists. Malicious URLs can cause incorrect postMessage domains.
<* Source: Erling Ellingsen
Link: http://support.apple.com/kb/HT6254
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
Apple has released a Security Bulletin (HT6254) and corresponding patches for this:
HT6254: About the security content of Safari 6.1.4 and Safari 7.0.4
Link: http://support.apple.com/kb/HT6254
Patch download: http://www.apple.com/support/downloads/
This article permanently updates the link address: