First published: Fri Mar 12 2010(Updated: )
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | =4.0.2 | |
Safari | =4.0.1 | |
Safari | <=4.0.4 | |
Safari | =4.0.3 | |
Safari | =4.0 | |
Safari | =4.0.0b | |
<4.0.5 | ||
>=2.0<4.0 | ||
=11 | ||
=12 | ||
=13 | ||
=9.10 | ||
=10.04 | ||
=10.10 | ||
=11.2 | ||
=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0050 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2010-0050, you should update affected versions of Apple Safari to version 4.0.5 or later.
CVE-2010-0050 affects Apple Safari versions up to 4.0.4, including versions 4.0.0b to 4.0.4.
Yes, CVE-2010-0050 can cause a denial of service by crashing the Safari application.
CVE-2010-0050 is a use-after-free vulnerability found in the WebKit component of Apple Safari.