First published: Fri Mar 12 2010(Updated: )
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | =4.0.2 | |
Safari | =4.0.1 | |
Safari | <=4.0.4 | |
Safari | =4.0.3 | |
Safari | =4.0 | |
Safari | =4.0.0b | |
<=4.0.4 | ||
=4.0 | ||
=4.0.0b | ||
=4.0.1 | ||
=4.0.2 | ||
=4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0054 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
To fix CVE-2010-0054, upgrade to Apple Safari 4.0.5 or later.
CVE-2010-0054 affects Safari versions 4.0.0 to 4.0.4 including versions 4.0.1, 4.0.2, 4.0.3.
Attackers can exploit CVE-2010-0054 to execute arbitrary code or crash the application.
CVE-2010-0054 was reported in March 2010.