Mac OS X : Apple Safari < 6.1.3 / 7.0.3 Multiple Vulnerabilities

critical Nessus Plugin ID 73304

Synopsis

The remote host contains a web browser that is affected by multiple vulnerabilities.

Description

The version of Apple Safari installed on the remote Mac OS X host is a version prior to 6.1.3 or 7.0.3. It is, therefore, potentially affected by the following vulnerabilities related to the included WebKit components :

- Unspecified errors exist that could allow memory corruption, application crashes and possibly arbitrary code execution. (CVE-2013-2871, CVE-2013-2926, CVE-2013-2928, CVE-2013-6625, CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, CVE-2014-1294, CVE-2014-1298, CVE-2014-1299, CVE-2014-1300, CVE-2014-1301, CVE-2014-1302, CVE-2014-1303, CVE-2014-1304, CVE-2014-1305, CVE-2014-1307, CVE-2014-1308, CVE-2014-1309, CVE-2014-1310, CVE-2014-1311, CVE-2014-1312, CVE-2014-1313, CVE-2014-1713)

- An error exists related to IPC messages and 'WebProcess' that could allow an attacker to read arbitrary files.
(CVE-2014-1297)

Solution

Upgrade to Apple Safari 6.1.3 / 7.0.3 or later.

See Also

http://www.zerodayinitiative.com/advisories/ZDI-14-057/

http://support.apple.com/kb/HT6181

http://www.securityfocus.com/archive/1/531708/30/0/threaded

Plugin Details

Severity: Critical

ID: 73304

File Name: macosx_Safari7_0_3.nasl

Version: 1.15

Type: local

Agent: macosx

Published: 4/2/2014

Updated: 11/26/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-1303

Vulnerability Information

CPE: cpe:/a:apple:safari

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, MacOSX/Safari/Installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/1/2014

Vulnerability Publication Date: 7/10/2013

Reference Information

CVE: CVE-2013-2871, CVE-2013-2926, CVE-2013-2928, CVE-2013-6625, CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, CVE-2014-1294, CVE-2014-1297, CVE-2014-1298, CVE-2014-1299, CVE-2014-1300, CVE-2014-1301, CVE-2014-1302, CVE-2014-1303, CVE-2014-1304, CVE-2014-1305, CVE-2014-1307, CVE-2014-1308, CVE-2014-1309, CVE-2014-1310, CVE-2014-1311, CVE-2014-1312, CVE-2014-1313, CVE-2014-1713

BID: 66579, 66580, 66581, 66583, 66584, 66585, 66586, 66587, 61054, 63024, 63028, 63672, 66088, 66242, 66243, 66572, 66573, 66574, 66575, 66576, 66577, 66578

APPLE-SA: APPLE-SA-2014-04-01-1