| PROBLEM: | The Apple Webkit contains a memory corruption vulnerability. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code. |
| PLATFORM: | Mac OS X v10.4.10, v10.5.4 Mac OS X Server v10.4.10, v10.4 |
| DAMAGE: | Execute arbitrary code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A remote, unauthenticated attacker may be able to execute arbitrary code. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
7.5 5.9 (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C) |
[***** Start HT2163 *****]
Please visit Apple's Web site to view their
Apple Security Update 20008-004 and Mac OS X 10.5.4
http://support.apple.com/kb/HT2163
[***** End HT2163 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org