exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

safari-2.0.3.txt

safari-2.0.3.txt
Posted Apr 28, 2006
Authored by Yannick von Arx | Site yanux.ch

Apple Mac OS X Safari 2.0.3 Vulnerability: A vulnerability exists in Safari 2.0.3 (417.9.2) and perhaps in prior versions which causes the operating system to slow down SRCOD (Spinning Rainbow Cursor Of Death), and therefore, it's not possible to launch any applications like Terminal to kill the process. After several minutes Safari crashes.

tags | advisory
systems | apple, osx
SHA-256 | 1b1b00d7a05322c9df74a0bf3744fc5fa2b4665c1d920ba9ac0ca53cb19b8700

safari-2.0.3.txt

Change Mirror Download


Apple Mac OS X Safari 2.0.3 Vulnerability
=========================================

Release Date:
April 23th, 2006

Vendor:
Apple Computer Inc.

Tested on:
iBook G4 1.2 GHz with Mac OS X 10.4.5 (Build 8H14) + all Updates from Apple except "10.4.6 Update"
iBook G4 1.33 GHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple
PowerMac G4 Dual 867 MHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple
iMac G4 800 MHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple

Versions affected:
Safari 2.0.3 (417.9.2) latest version under 10.4.5 (Build 8H14) and perhaps prior versions
Safari 2.0.3 (417.9.2) latest version under 10.4.6 (Build 8I127) and perhaps prior versions

Overview:
A vulnerabilitiy exists in Safari 2.0.3 (417.9.2) and perhaps in prior versions which causes the operating system to slow down SRCOD (Spinning Rainbow Cursor Of Death), and therefore, it's not possible to launch any applications like Terminal to kill the process. After several minutes Safari crashes.

Technical Details:
Create a new File with following code ...

<HTML>
<TABLE>
<TR><TD ROWSPAN=2000000000>

.. then save it as a .html file (example.html) now open it in Safari. The application takes a lot of CPU and RAM slowing down the operating system SRCOD (Spinning Rainbow Cursor Of Death), and it is no longer possible to use OSX even "apple" + "ALT" + "ESC" is working very slow!
Go around and pull the power cable out or press the startbutton for a while to shut down the computer.

For an expample klick at the link with Safari (WARNING: That crashes Safari after several minutes an first the SRCOD (Spinning Rainbow Cursor Of Death) is there for all the time!) http://www.yanux.ch/exploits/safari/example.html

Report:
iMac G4 800 MHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple
http://www.yanux.ch/exploits/safari/bugreport_imac_g4.txt

Vendor Status:
Apple has notified of this issues on 04/23/2006

Solution:
Currently no patches have been released for this vulnerability.

Discovered by:
Yannick von Arx
yannick[dot]vonarx[at]yanux[dot]ch

____________________________

e-mail:yannick.vonarx@yanux.ch
web: www.yanux.ch



------
freemails.ch - Free Swiss E-Mails

Webhosting nach Mass bereits ab CHF 5.50: www.hostplace.ch


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close