New Digital Computer
April 17th, 2008 at 1:14 am
Apple plugs Pwn2Own winning vulnerability
Apple plugged the winning vulnerability in the Pwn2own contest on Wednesday in a Safari update. In an update for Safari (3.1.1), Apple fixed the following vulnerabilities: CVE-2008-1026, also known as the flaw that won hacker Charlie Miller $10,000.in the Pwn2Own contest at CanSecWest. This patch covers a vulnerability that allowed a code execution attack via a maliciously crafted Web page. Here's Apple's description: A heap buffer overflow exists in WebKit's handling of JavaScript regular expressions. The issue may be triggered via JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Affected OSes: Mac OS...
Recent Posts
- EyeWonder malware incident affects popular web sites
- Blogging live from Spiral Jetty
- Employee shot, wounded at Virginia Apple store
- Rural energy grant deadline approaches: Aids renewable energy technology investments
- iPhone 3GS jailbreak, ‘purplera1n,’ hits Web
- Gadget Gal’s daily deals: 60 GB Apple iPod, 250 GB Archos 5, Logitech keyboard and mouse combo
- Apple patents point to haptics, fingerprints, RFID
- Oracle’s FusionFest: BEA underneath, dogfood, Sun on the horizon
- Oracle Fusion 11g Middleware: Executed according to plan
- "Windows 7 is the same as Ubuntu"
Categories
Archives