First published: Thu Jan 18 2007(Updated: )
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OmniGroup OmniWeb | =5.5.3 | |
Apple Mobile Safari | =2.0.4_419.3 | |
Apple WebKit | =build_18794 | |
Apple iOS and macOS | =10.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0342 is categorized as a denial of service vulnerability.
CVE-2007-0342 allows remote attackers to cause application crashes through malformed HTML content.
CVE-2007-0342 affects OmniWeb 5.5.3, Apple Safari 2.0.4_419.3, and Apple WebKit build 18794.
Mitigating CVE-2007-0342 involves updating to the latest versions of the affected software.
Exploitation of CVE-2007-0342 typically results in a null dereference and crashes of the web application.