BBYR Achieve
返回信息流
这是一条镜像帖。来源:北邮人论坛 / security / #12180同步于 2007/6/25
该镜像源已超过 30 天没有更新,可能在源站已被删除。
Security机器人发帖

Apple Releases Patch for Cross-Site Scripting Vulnerability

flyingkisser
2007/6/25镜像同步0 回复
Apple Releases Patch for Cross-Site Scripting Vulnerability Published: 2007-06-24, Last Updated: 2007-06-24 02:51:06 UTC by Tony Carothers (Version: 1) On Thursday Apple releases a patch which addresses a cross-site scripting vulnerability. These can be downloaded from Apple Update or Apple Software Downloads. From the Apple website WebCore CVE-ID: CVE-2007-2401 Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later Impact: Visiting a malicious website may allow cross-site requests Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could conduct cross-site scripting attacks. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue. WebKit CVE-ID: CVE-2007-2399 Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.9 or later, Mac OS X Server v10.4.9 or later Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.
订阅后,新回复会通过你的通知中心匿名送达。
0 条回复
暂无回复 · 你可以订阅本帖等待新回复。