First published: Mon Jul 14 2008(Updated: )
WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone | =1.0 | |
Apple iPhone | =1.1 | |
Apple iPhone | =1.1.3 | |
Apple iPod touch | <=1.1.4 | |
Apple iPod touch | =1.1 | |
Apple iPod touch | =1.1.1 | |
Apple iPod touch | =1.1.2 | |
Apple iPod touch | =1.1.3 | |
iStyle @cosme iPhone OS | <=1.1.4 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
Apple Mobile Safari |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2317 has a high severity rating due to the potential for remote code execution and application crashes.
To fix CVE-2008-2317, update your Apple Safari browser to the latest version to mitigate the vulnerability.
CVE-2008-2317 affects certain versions of Apple Safari prior to the security update released in 2008.
Yes, CVE-2008-2317 can cause heap corruption which may lead to data loss or corruption during its exploitation.
CVE-2008-2317 is less of a concern for current users if they maintain updated software versions, as the vulnerability has been addressed.