Apple Safari Webkit Button First-Letter Style Rendering Code Execution
Publish date: February 14, 2011
Severity: CRITICAL
CVE Identifier: CVE-2010-1392
Advisory Date: FEB 14, 2011
DESCRIPTION
Use-after-free vulnerability in WebKit in Apple Safari before 5.0
on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4,
allows remote attackers to execute arbitrary code or cause a denial of service
(application crash) via vectors related to HTML buttons and the first-letter CSS
style.
TREND MICRO PROTECTION INFORMATION
Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1004374
Trend Micro Deep Security DPI Rule Name: 1004374 - Apple Safari Webkit Button First-Letter Style Rendering Code Execution
AFFECTED SOFTWARE AND VERSION
- Apple Safari 4.0
- Apple Safari 4.0.0b
- Apple Safari 4.0.1
- Apple Safari 4.0.2
- Apple Safari 4.0.3
- Apple Safari 4.0.4
- Apple Safari 4.0.5
- Apple Webkit
Featured Stories
- Abusing Argo CD, Helm, and Artifact Hub: An Analysis of Supply Chain Attacks in Cloud-Native ApplicationsWe provide an overview of cloud-native tools and examine how cybercriminals can exploit their vulnerabilities to launch supply chain attacks.Read more
- Trends and Shifts in the Underground N-Day Exploit MarketOur two-year research provides insights into the life cycle of exploits, the types of exploit buyers and sellers, and the business models that are reshaping the underground exploit market.Read more
- The Nightmares of Patch Management: The Status Quo and BeyondWe discuss the challenges that organizations face in managing endpoint and server patches.Read more
- Identifying Weak Parts of a Supply ChainMalicious attacks have consistently been launched on weak points in the supply chain. Like all attacks, these will evolve into more advanced forms. Software development, with multiple phases that could be placed at risk, is particularly vulnerable.Read more