First published: Wed Dec 18 2013(Updated: )
WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=6.1 | |
Apple Mobile Safari | =6.0 | |
Apple Mobile Safari | =6.0.1 | |
Apple Mobile Safari | =6.0.2 | |
Apple Mobile Safari | =6.0.3 | |
Apple Mobile Safari | =6.0.4 | |
Apple Mobile Safari | =6.0.5 | |
Apple Mobile Safari | =7.0 | |
Apple WebKit | ||
Apple iTunes for Windows | <=12.0 | |
iStyle @cosme iPhone OS | <=7.0.6 | |
tvOS | <=6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5198 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2013-5198, you should update Apple Safari to version 6.1.1 or later, or 7.0.1 or later.
CVE-2013-5198 affects Apple Safari versions prior to 6.1.1 and 7.x prior to 7.0.1.
Yes, CVE-2013-5198 may also affect other products that utilize WebKit, including some versions of iTunes and iPhone OS.
Users may experience application crashes or allow attackers to execute arbitrary code by visiting a crafted website.