CVE-2007-3186: Critical severity Safari vulnerability
Published Jun 12, 2007
·Updated
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
Affected Software
8 affected components
Safari=2.0.1
Safari=3.0.1
Safari=2.0.3
Safari=2.0.2
Safari=2.0
Safari=2.0.4
Safari
Safari=3.0
Event History
Jun 12, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
Systems running Apple Safari Beta 3.0.1 for Windows are exposed. Exploitation can be performed remotely and does not require authentication.
2
What does an attacker need to do to exploit it?
An attacker needs to cause Safari to process an IFRAME whose SRC URI contains shell metacharacters. A gopher URI is identified as a demonstrated delivery vector.
3
What is the potential impact of successful exploitation?
Successful exploitation allows remote execution of arbitrary commands, with confidentiality, integrity, and availability all affected.