First published: Fri Mar 12 2010(Updated: )
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =4.0.2 | |
Apple Mobile Safari | =4.0.1 | |
Apple Mobile Safari | <=4.0.4 | |
Apple Mobile Safari | =4.0-beta | |
Apple Mobile Safari | =4.0.3 | |
Apple Mobile Safari | =4.0 | |
Apple Mobile Safari | =4.0.0b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0053 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2010-0053, upgrade Apple Safari to version 4.0.5 or later.
Users running Apple Safari versions 4.0.4 and earlier are affected by CVE-2010-0053.
CVE-2010-0053 can be exploited through remote attacks that utilize malicious CSS properties.
Exploitation of CVE-2010-0053 may lead to arbitrary code execution or cause the application to crash.