Apple Safari 3 for Windows - 'Document.Location' Denial of Service



EKU-ID: 35294 CVE: OSVDB-ID:
Author: azizov Published: 2007-06-16 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/24499/info

Apple Safari for Windows is prone to a denial-of-service vulnerability because it fails to properly handle user-supplied input.

An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.

Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions.

Safari 3.0 and 3.0.1 public beta for Windows are reported vulnerable.

NOTE: At the time of writing, Symantec was unable to reproduce this vulnerability. We are investigating this issue further and will update this BID as more information emerges.

<script type='text/javascript'> document.location = ''; </script>