Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Details : SecurityAlert

  Topic : Safari 3.1.1 Multiple Vulnerabilities for windows
  SecurityAlert : 3833
  CVE : CVE-2008-1999
  CVE : CVE-2008-2000
  CVE : CVE-2008-2001
  SecurityRisk : Medium  alert  (About)
  Remote Exploit : Yes
  Local Exploit : No
  Exploit Given : Yes
  Credit : jplopezy gmail com
  Published : 28.04.2008

  Affected Software : Safari 3.1.1



  Advisory Text :  

I found a number of flaws in the browser Safari 3.1.1.

The first is a way to make spoofing ( "falsify direction"). Is that as we
all know many browser to put eg

A (at) domain (dot) com [email concealed]

This attempt to connect to the domain after the @ user and use the first
word or letters that we have, this is not today because it is obvious that
the first two are together and the second most of the browser asks for
permission to such action. What's going on safari in this technique that
makes it possible to do this not just to you and asks permission to enter
site, the second is that there is some character who safari interprets as
"invisible" by creating a link with that of user domain fake followed by a
large number of characters "invisible" and lastly with the @ domain to
enter this will lead to falsification of the site.

Another flaw is that the safari when writing on the same page with a
"document.write" with an infinite while this may result in the browser is
broken, causing the following fall

Access violation when writing to [0FDFFFEE]

Finally there is a certain character that causes safari break when it comes
to making a link to "file: / /" this creates the following as a result
fails

Access violation when reading [00000004]

Good will leave the proof of concept

http://es.geocities.com/jplopezy/pruebasafari3.html

And the greetings!

Juan Pablo Lopez Yacubian

fuzzertina.blogspot.com





  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

» Apache-SSL memory
   disclosure

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.