Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6091 | vdb entry signature |
http://lostmon.blogspot.com/2009/01/safari-for-windows-321-remote-http-uri.html | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48284 | vdb entry |
http://www.securityfocus.com/bid/33481 | vdb entry exploit |