First published: Wed Jul 25 2012(Updated: )
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=5.1.7 | |
Apple Mobile Safari | =1.0 | |
Apple Mobile Safari | =1.0-beta | |
Apple Mobile Safari | =1.0-beta2 | |
Apple Mobile Safari | =1.0.0 | |
Apple Mobile Safari | =1.0.0b1 | |
Apple Mobile Safari | =1.0.0b2 | |
Apple Mobile Safari | =1.0.1 | |
Apple Mobile Safari | =1.0.2 | |
Apple Mobile Safari | =1.0.3 | |
Apple Mobile Safari | =1.0.3-85.8 | |
Apple Mobile Safari | =1.0.3-85.8.1 | |
Apple Mobile Safari | =1.0b1 | |
Apple Mobile Safari | =1.1 | |
Apple Mobile Safari | =1.1.0 | |
Apple Mobile Safari | =1.1.1 | |
Apple Mobile Safari | =1.2 | |
Apple Mobile Safari | =1.2.0 | |
Apple Mobile Safari | =1.2.1 | |
Apple Mobile Safari | =1.2.2 | |
Apple Mobile Safari | =1.2.3 | |
Apple Mobile Safari | =1.2.4 | |
Apple Mobile Safari | =1.2.5 | |
Apple Mobile Safari | =1.3 | |
Apple Mobile Safari | =1.3.0 | |
Apple Mobile Safari | =1.3.1 | |
Apple Mobile Safari | =1.3.2 | |
Apple Mobile Safari | =1.3.2-312.5 | |
Apple Mobile Safari | =1.3.2-312.6 | |
Apple Mobile Safari | =2 | |
Apple Mobile Safari | =2.0 | |
Apple Mobile Safari | =2.0.0 | |
Apple Mobile Safari | =2.0.1 | |
Apple Mobile Safari | =2.0.2 | |
Apple Mobile Safari | =2.0.3 | |
Apple Mobile Safari | =2.0.3-417.8 | |
Apple Mobile Safari | =2.0.3-417.9 | |
Apple Mobile Safari | =2.0.3-417.9.2 | |
Apple Mobile Safari | =2.0.3-417.9.3 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =3 | |
Apple Mobile Safari | =3.0 | |
Apple Mobile Safari | =3.0.0 | |
Apple Mobile Safari | =3.0.0 | |
Apple Mobile Safari | =3.0.0b | |
Apple Mobile Safari | =3.0.0b | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.0.1-beta | |
Apple Mobile Safari | =3.0.1b | |
Apple Mobile Safari | =3.0.1b | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =3.0.2b | |
Apple Mobile Safari | =3.0.2b | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =3.0.3b | |
Apple Mobile Safari | =3.0.3b | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =3.0.4b | |
Apple Mobile Safari | =3.0.4b | |
Apple Mobile Safari | =3.1.0 | |
Apple Mobile Safari | =3.1.0 | |
Apple Mobile Safari | =3.1.0b | |
Apple Mobile Safari | =3.1.0b | |
Apple Mobile Safari | =3.1.1 | |
Apple Mobile Safari | =3.1.1b | |
Apple Mobile Safari | =3.1.2 | |
Apple Mobile Safari | =3.1.2b | |
Apple Mobile Safari | =3.2.0 | |
Apple Mobile Safari | =3.2.0b | |
Apple Mobile Safari | =3.2.1 | |
Apple Mobile Safari | =3.2.1b | |
Apple Mobile Safari | =3.2.2 | |
Apple Mobile Safari | =3.2.2b | |
Apple Mobile Safari | =4.0 | |
Apple Mobile Safari | =4.0-beta | |
Apple Mobile Safari | =4.0.0b | |
Apple Mobile Safari | =4.0.1 | |
Apple Mobile Safari | =4.0.2 | |
Apple Mobile Safari | =4.0.3 | |
Apple Mobile Safari | =4.0.4 | |
Apple Mobile Safari | =4.0.5 | |
Apple Mobile Safari | =4.1 | |
Apple Mobile Safari | =4.1.1 | |
Apple Mobile Safari | =4.1.2 | |
Apple Mobile Safari | =5.0 | |
Apple Mobile Safari | =5.0.1 | |
Apple Mobile Safari | =5.0.2 | |
Apple Mobile Safari | =5.0.4 | |
Apple Mobile Safari | =5.0.5 | |
Apple Mobile Safari | =5.0.6 | |
Apple Mobile Safari | =5.1 | |
Apple Mobile Safari | =5.1.1 | |
Apple Mobile Safari | =5.1.2 | |
Apple Mobile Safari | =5.1.3 | |
Apple Mobile Safari | =5.1.4 | |
Apple Mobile Safari | =5.1.5 | |
Apple Mobile Safari | =5.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3640 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
To mitigate CVE-2012-3640, it is recommended to upgrade Apple Safari to a version later than 5.1.7.
CVE-2012-3640 affects Apple Safari versions prior to 6.0, including all versions from 1.0 up to 5.1.7.
Exploitation of CVE-2012-3640 can lead to arbitrary code execution, potentially allowing attackers to control the affected system.
While the best solution is to upgrade Safari, users can enhance security by avoiding untrusted websites until a patch is applied.