PT-2017-7823 · Apple · Safari Technology Preview

Kamil Frankowicz

·

Publicado

2017-04-03

·

Atualizado

2017-04-11

·

CVE-2016-10226

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Safari Technology Preview Release 18
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, via crafted JavaScript code. This is related to the mishandling of code in the operatorString function, and involves files such as MacroAssemblerARM64.h, MacroAssemblerX86Common.h, and WasmB3IRGenerator.cpp.
Recommendations For Safari Technology Preview Release 18, consider avoiding the execution of crafted JavaScript code until a fix is available. As a temporary workaround, restricting JavaScript execution may help minimize the risk of exploitation.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10226

Produtos afetados

Safari Technology Preview