Showing posts with label iPhone. Show all posts
Showing posts with label iPhone. Show all posts

Apple patches Pwn2Own iPhone OS vulnerabilities


Apple has released a critical update for its flagship iOS mobile operating system to fix several gaping security holes, including a few that were used in successful exploits at this year’s CanSecWest Pwn2Own contest.

The new iOS 4.3.2 software update, which is available for download via iTunes, provides cover for five documented security problems, including vulnerabilities exploited by Charlie Miller (iPhone) and a team of researchers who broke into RIM’s BlackBerry smartphone.

The raw details:

  • QuickLook: A memory corruption issue existed in QuickLook’s handling of Microsoft Office files. Viewing a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution. Credit to Charlie Miller and Dion Blazakis working with TippingPoint’s Zero Day Initiative.
  • WebKit: An integer overflow issue existed in the handling of nodesets. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. Credit to Vincenzo Iozzo, Willem Pinckaers, Ralf-Philipp Weinmann, and an anonymous researcher working with TippingPoint’s Zero Day Initiative.
  • WebKit: A use after free issue existed in the handling of text nodes. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. Credit to Vupen Security working with TippingPoint’s Zero Day Initiative, and Martin Barbella.

The iOS update also fixes the Comodo certificate trust policy problem that allowed an attacker with a privileged network position to intercept user credentials or other sensitive information. This issue was also fixed in separate Safari and Mac OS X updates.

[Source: zdnet]

Pwn2Own hacker: Apple Safari is 'easy pickings'

Charlie Miller, the security researcher who won last year’s Pwn2Own hacker contest, is predicting that Apple’s Safari browser will be the easiest target this year.

In a note posted on the popular Daily Dave mailing list, Miller describes Safari as “easy pickin’s” and forecasts that at least four zero-day Safari flaws will be used during the contest at CanSecWest later this month.

[ SEE: Pwn2Own hacker contest targets browsers, smart phones ]

This year’s contest will pit hackers against browsers and smart phones with Internet Explorer, Firefox, Safari, Opera and Chrome among the high-profile targets. It will also include attacks against fully patched BlackBerry, Android, iPhone, Symbian and Windows Mobile phones in their default configurations.

Here are Miller’s predictions:

  • Safari: hacked by 4 different people. Easy pickin’s as usual.
  • Android: hacked by 1 person. Not too tough but no one owns one.
  • IE8, Firefox: Survive unscathed. The bugs to exploit equation is too hard for $5k.
  • iPhone, Symbian: Survive due to non-executable heap.
  • Blackberry, Windows Mobile, Chrome: I don’t know enough to say anything intelligent. That said, they’re probably hard/obscure and so survive.

Last year, Miller exploited a Safari flaw to hijack a fully patched MacBook Pro machine. He is also known for launching successful attacks against Apple’s iPhone and Google’s Android platform.

ALSO SEE: 10 questions for MacBook hacker Dino Dai Zovi

[Source: zdnet]

iPhone update kills 12 security bugs

iPhone update kills 12 security bugsApple has released iPhone OS 2.2 with patches for 12 documented security flaws, some very serious.

The vulnerabilities covered by the patch (which also affect iPod Touch) could allow remote code execution, information theft, software crashes and weakened encryption settings.

The skinny on this batch of updates:

  • CVE-2008-2321: CoreGraphics contains memory corruption issues in the processing of arguments. Passing untrusted input to CoreGraphics via an application, such as a web browser, may lead to an unexpected application termination or arbitrary code execution. Credit to Michal Zalewski of Google for reporting this issue.
  • CVE-2008-2327: Multiple uninitialized memory access issues exist in libTIFF’s handling of LZW-encoded TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-1586: A memory exhaustion issue exists in the handling of TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected device reset. Credit to Sergio ’shadown’ Alvarez of n.runs AG for reporting this issue.
  • CVE-2008-4227: The encryption level for PPTP VPN connections may revert to a previous lower setting. This update addresses the issue by properly setting the encryption preferences. Credit to Stephen Butler of the University of Illinois of Urbana-Champaign for reporting this issue.
  • CVE-2008-4211: A signedness issue in Office Viewer’s handling of columns in Microsoft Excel files may result in an out-of-bounds
    memory access. Viewing a maliciously crafted Microsoft Excel file may lead to an unexpected application termination or arbitrary code
    execution. Apple discovered this bug internally.
  • CVE-2008-4228: iPhone provides the ability to make an emergency call when locked. Currently, an emergency call may be placed to any number. A person with physical access to an iPhone may take advantage of this feature to place arbitrary calls which are charged to the iPhone owner.
  • CVE-2008-4229: The Passcode Lock feature is designed to prevent applications from being launched unless the correct passcode is
    entered. A race condition in the handling of device settings may cause the Passcode Lock to be removed when the device is restored
    from backup. This may allow a person with physical access to the device to launch applications without the passcode. Credit to Nolen Scaife for reporting this issue.
  • CVE-2008-4230: If an SMS message arrives while the emergency call screen is visible, the entire SMS message is displayed, even if the “Show SMS Preview” preference was set to “OFF”. This update addresses the issue by, in this situation, displaying only a notification that a SMS message has arrived, and not its content.
  • CVE-2008-4231: A memory corruption issue exists in the handling of HTML table elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. Credit to Haifei Li of Fortinet’s FortiGuard Global
    Security Research Team for reporting this issue.
  • CVE-2008-4232: Safari allows an iframe element to display content outside its boundaries, which may lead to user interface spoofing. Credit to John Resig of Mozilla Corporation for reporting this issue.
  • CVE-2008-4233: If an application is launched via Safari while a call approval dialog is shown, the call will be placed. This may allow a maliciously crafted website to initiate a phone call without user interaction. Additionally, under certain circumstances it may be
    possible for a maliciously crafted website to block the user’s ability to cancel dialing for a short period of time. Credit to Collin Mulliner of Fraunhofer SIT for reporting this issue.
  • CVE-2008-3644: Disabling autocomplete on a form field may not prevent the data in the field from being stored in the browser page cache. This may lead to the disclosure of sensitive information to a person with physical access to an unlocked device.

It should be mentioned that several known phishing and spamming flaws in iPhone are not yet addressed.

[Source: zdnet]

Google Android vulnerable to drive-by browser exploit

Google Android vulnerable to drive-by browser exploitThe Google Android operating system is vulnerable to a serious security vulnerability that allows malicious hackers to launch drive-by browser attacks, according to alert from a security research outfit.

Technical details of the vulnerability, which occurs because Google Android uses an unpatched open-source software package, is being kept under wraps until a patch is available.

[ SEE: Android security team appeals to hackers ]

Google was notified of this issue on October 20th, 2008.

According to a warning from Independent Security Evaluators (the company that found the first iPhone code execution flaw), this particular security vulnerability “was known and fixed in the relevant software package,” but Google used an older, still vulnerable version.

The Google Android OS powers the T-Mobile G1 by HTC, a device that’s currently in stores in the United States.

[ SEE: Research firm: Google Android SDK has multiple vulnerabilities ]

  • A user of an Android phone who uses the web browser to surf the internet may be exploited if they visit a malicious page. Upon visiting the malicious site, the attacker can run any code they wish with the privileges of the web browser application. We have a very reliable exploit for this issue for demonstration purposes.

The researchers, however, acknowledged that the impact of this attack is “somewhat limited” because of the way Google Android is designed.

  • A successful attacker will have access to any information the browser may use, such as cookies used for accessing sites, information put into web application form fields, saved passwords, etc. They may also change the way the browser works, tricking the user into entering sensitive information. However, they can not control other, unrelated aspects of the phone, such as dialing the phone directly.
[Source: zdnet]

iPhone hits another security speedbump


iPhone hits another security speedbump

Apple’s ongoing struggles with poor security-related design choices have extended to the iPhone. According to security researcher Aviv Raff, everyone’s favorite mobile device is vulnerable to two separate security weaknesses that expose millions of users to phishing and spamming attacks.


[ SEE: Apple hasn’t learned from past security mistakes ]

Raff, a bug finder who regularly reports flaws in modern Web browsers, discovered that it’s easy to mask a link to a malicious phishing Web site because of the way the iPhone’s Mail application handles the display of links.

When the mail message is in HTML format, the text of links can be set to a different URL than the actual link. In most mail clients (e.g. on your PC / Mac), you can just hover the link and get a tooltip which will tell you the actual URL that you are about to click.

In iPhone it’s a bit different. You need to click the link for a few seconds in order to get the tooltip. Now, because the iPhone screen is small, long URLs are automatically cut off in the middle. So, instead of “hxxp://www.somedomain.com/verylongpath/verylongfilename”, you will get in the tooltip something like “www.somedomain.com/very…ilename”.

[ SEE: Apple patches 10 iPhone security holes ]

The problem here, Raff explains, is that an attacker can set a long subdomain (~24 characters) that, when cut off in the middle, will look as if it’s a trusted domain.

The spamming bug, described by Raff as “a pretty dumb design flaw,” allows the harvesting of “live” e-mail addresses simply by sending rigged images to targets checking e-mail on iPhones.

Whenever you view an HTML mail message which contains images, a request is made to a remote server in order to get the image. Most of the mail clients today requires you to approve the download of the images. This is done for a good reason.

If the images were downloaded automatically, the spammer who controls the remote server will know that you have read the message, and will mark your mail account as active, in order to send you more spam. This “feature” is also known as “Web Bug”

The iPhone’s Mail application downloads all images automatically, and there is NO WAY to disable this feature!

[ SEE: Apple caught neglecting iPhone security ]

Raff said he provided details of these issues to Apple more than two month ago.

I’ve asked Apple several times for a schedule, but they have refused to provide the fix date. Three versions (v2.0.1, v2.02, v2.1) have been released since I provided them with the details, and they are still “working on it”. Therefore, I’ve decided to publicly disclose the technical details.

Separately, there’s an unpatched SMS privacy hole when the iPhone is placed in emergency call mode.

Apple is notoriously slow to fix iPhone flaws so if you’re nervous about these risks, you should be very careful when using Mail on the device.

[Source: zdnet]

Dropping the iPhone NDA is good for security

Last week Apple lifted their NDA on iPhone developers, freeing them to discuss amongst themselves how to properly build applications. This decision is a “good thing” for not just applications but also application security on the iPhone.

The iPhone NDA was antithetical to how developers work. Developers learn from code snippets and design patterns. They rarely invent functions from scratch, and will look at how previous applications were built to decide how to build their current projects. This isn’t because developers are unimaginative, but because they recognize there are a million ways of doing something but only a handful are efficient, effective, and ultimately won’t cause a security event that will bite you in the rear somewhere down the road.

Over the past decade, developers and security consultants have worked to fix millions of lines of code that were created without an understanding of their possible security implications. Software vulnerabilities with names like “buffer overflow” and “double free” are the result of improper coding practices. The software development community started to produce programming guides that contained code describing the right and wrong way of handing C strings, SQL queries, and cryptography. Without this open discussion, we would still be fighting basic programming flaws in widespread binaries, which is something that has largely slowed down several years ago.

I don’t know if there are any programming flaw syndromes that are already present in iPhone applications. I would be surprised if there were any, given the programming language used for iPhone apps as well as their use profile. If flaws were to come up, though, having an NDA on programming techniques would make the flaws far more difficult to repair.

[Source: zdnet]

Apple security not ready for enterprise prime-time

Guest editorial by Andrew Storms

Apple security not ready for enterprise prime-timeLast week Apple proved that they are not ready for prime time enterprise relationships.

Apple has tried to position the iPhone as enterprise-ready, but this last round of software updates demonstrated beyond a shadow of a doubt how far they have to go to understand the enterprise mentality.

On September 9th, Apple released updates to some 20 security vulnerabilities that included updates to QuickTime, iTunes and other software. On September 12th, Apple released iPhone version 2.1, which was intended to fix 8 security holes and repair 3G connections problems. On September 15th, Apple released updates to OSX that includes fixes to nearly 70 security problems. On September 16th, Apple released updates to Remote Desktop, again fixing more security problems.


[ SEE: Apple plugs iPhone code execution holes ]

In the matter of 8 days, Apple released updates to every one of its major platforms and applications. Those updates included over 100 security updates spanning Mac OSX, Windows Vista, Windows XP, the iPhone and the iPod Touch. So how did that affect enterprise security teams?

On September 9th, security teams met, reviewed the updates, set priorities and assigned resources. Remember that unlike other vendors, Apple did not provide any advanced notification on timing or the magnitude of the updates. This update caught everyone off guard. Then again, without notice, security teams were brought back to the meeting room to discuss the updates on September 12th (repeat drill above). Then yes, you guessed it, same story again on September 15th and again on the16th. Who knows, maybe by the time this is published, there will be anothTime for Apple to embrace a security development lifecycleer update?

Every IT staff is already resource constrained and some teams always are in a passive firefighting mode. If your security team thought it was almost caught up with Apple updates already issued this year, the last week set you back significantly and probably pushed other, potentially critical, scheduled work into a wait state.

[ SEE: iPhone passcode lock rendered useless ]

Mind you that last week’s updates just didn’t stop at OSX. Even if you run a Windows shop that permits QuickTime or iTunes, you couldn’t ignore this torrent of updates. The impact of this random update cycle from Apple may be serious enough that some companies decide to limit or stop using Apple hardware or software entirely. After last week, IT teams running ragged by the deluge of unannounced patches are wishing they could make the policy decision to get all Apple software off the network. With this kind of uncertainty and apparent lack of planning, who can blame them?

Apple had an opportunity to embrace the enterprise by showing leadership in its software development lifecycle. And while we would never expect Apple to follow Microsoft’s footsteps, they could have learned what works and what doesn’t in the enterprise, and then in their Apple way, take it to the next level. I think that’s what many Mac fans in the IT department were hoping for. Too bad we had such a big let down last week.

[ SEE: Apple plugs gaping QuickTime security holes ]

We’d like to see Apple embrace public discourse regarding security updates. We respectfully suggest that Apple sit with enterprise managers, listen and then take the information they receive and build a process that doesn’t leave IT teams staggering.

Instead of wasting the valuable time and resources of their target customers, Apple could take the opportunity to perform the way they have done in other markets. This assumes that Apple can apply their creative, customer focused energy that has made them a powerhouse in the consumer market and put some of that effort into collaborative partnerships.

[ SEE: Apple mega-patch covers 34 Mac OS X security issues ]

We’d love to see Apple step up and change the game in software development lifecycle, or at least learn to play the game with the best of them. Apple, we’re rooting for you, but it’s gonna take a whole lot more than you’ve shown us so far. And we have to tell ya, hip and cool can only take you so far in the enterprise.

* Andrew Storms is director of security operations at nCircle, where he is responsible for setting and enforcing the company’s security compliance programs as well as overseeing day-to-day operations for the IT department. His writing can be found on nCircle’s 360 Security blog.

* Image source: charliekwalker’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

The iPhone reset feature, or why throttling matters

Throttling is a fundamental technique that finds numerous applications in information security. It helps buy time for a security team to decide the proper course of action for remediating a problem. In a previous article I briefly mentioned its utility for social network’s anti-spam efforts. Throttling of malicious activity can prove useful for security of consumer products as well, as shown by a patch delivered this past week to a popular handset.

On Friday Apple released iPhone firmware 2.1, an update that brought many bug fixes and security patches to the platform. One new feature listed is the option to “wipe data after ten failed passcode attempts”. I immediately thought about possible ways this feature could be exploited by someone to maliciously wipe a handset. Let’s say you are at a bar with a few friends after work, and one of them happens to think an amusing practical joke would be to blank your handset. Another scenario would be if your child picked up your phone and decided to attempt to log in, but repeatedly entered the wrong passcode. In both cases a few extra minutes can make the difference between having a phone that is still immediately usable and one that is not.

Apple included staged throttles on the passcode screen that can create this extra time. After 6 passcode failures, the user is required to wait 1 minute before attempting again. Failing 7 and 8 times in a row incurs 5 and 15 minute pauses. I didn’t want to see how long I would have to wait to use my phone after 9 failures. Collectively, the incorrect passcode throttles will generate at least 20 minutes of delay before someone can wipe your handset, more than enough time to intervene and stop someone from playing with your handset if it is still physically near you.

Having a passcode throttle does not prevent the device from being stolen, nor does it prevent someone from gaining access to the data. A phone will be stolen regardless of whether or not the thief can use it him or herself, and the winners in the data theft game are the attackers who have the most patience. What the throttle does provide you, however, is a little more time to take a remediating action, or, in other words, find your phone and put it back in your pocket.

[Source: zdnet]


Apple plugs iPhone code execution holes

Apple plugs iPhone code execution holesApple’s long-awaited iPhone 2.1 software update was released today with patches for at least eight security vulnerabilities, some of which could lead to remote code execution attacks.

The most serious of the documented flaws affect the built-in Safari browser and could lead to code execution if an iPhone user is tricked into surfing to a booby-trapped Web site.

[ SEE: iPhone passcode lock rendered useless ]

The update also fixes the previously reported passcode lock weakness and an issue in mDNSResponder that puts users at risk of DNS cache poisoning attacks.

Here’s the skinny on the security patches in iPhone 2.1:

  • Application Sandbox (CVE-2008-3631): The Application Sandbox does not properly enforce access restrictions between third-party applications. This may allow a third-party application to read files in another third-party application’s sandbox, and lead to the disclosure of sensitive information.
  • CoreGraphics (CVE-2008-1806, CVE-2008-1807, CVE-2008-180): Multiple vulnerabilities exist in FreeType v2.3.5, the most serious of which may lead to arbitrary code execution when accessing maliciously crafted font data.
  • mDNSResponder (CVE-2008-1447): mDNSResponder provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow a remote attacker to perform DNS cache poisoning attacks. As a result, applications that rely on mDNSResponder for DNS may receive forged information.
  • Networking (CVE-2008-3612): TCP initial sequence numbers are sequentially generated. Predictable initial sequence numbers may allow a remote attacker to create a spoofed TCP connection or insert data into an existing TCP connection.
  • Passcode Lock (CVE-2008-3633): The Passcode Lock feature is designed to prevent applications from being launched unless the correct passcode is entered. An implementation issue in the handling of emergency calls allows users with physical access to an iPhone to launch an application without the passcode by double clicking the home button in emergency call.
  • WebKit (CVE-2008-3632): A use-after-free issue exists in WebKit’s handling of CSS import statements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of document references.

ALSO SEE: AT&T iPhones exposed to DNS cache poisioning? Or not? and Apple caught neglecting iPhone security

[Source: zdnet]

Apple plugs gaping QuickTime security holes

Code execution holes haunt QuickTimeApple today released a major makeover to its iTunes and QuickTime software products, fixing at least 11 documented security vulnerabilities that could lead to Mac and PC takeover attacks.

QuickTime 7.5.5, which should be considered an “extremely critical” update, address nine different vulnerabilities that could cause some serious damage if a Windows or Mac OS X user is tricked into viewing a rigged movie file. The iTunes 8 update addresses two separate bugs that could put users at risk of information disclosure.

Full details on the vulnerabilities and patches:

QUICKTIME 7.5.5

  • CVE-2008-3615: An uninitialized memory access issue exists in the third-party Indeo v5 codec for QuickTime, which does not ship with QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3
  • CVE-2008-3635: A stack buffer overflow exists in the third-party Indeo v3.2 codec for QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3.
  • CVE-2008-3624: A heap buffer overflow exists in QuickTime’s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution. Affects Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3.
  • CVE-2008-3625: A stack buffer overflow exists in QuickTime’s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution.
    Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3614: An integer overflow exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3.
  • CVE-2008-3626: A memory corruption issue exists in QuickTime’s handling of STSZ atoms in movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3627: Multiple memory corruption exist in QuickTime’s handling of H.264 encoded movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3628: An invalid pointer issue exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. Available for Windows Vista, XP SP2 and SP3.
  • CVE-2008-3629: An out-of-bounds read issue exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination. Affects Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3.

iTunes 8

  • CVE-2008-3634: When the firewall is configured to block iTunes Music Sharing and the user enables iTunes Music Sharing in iTunes, a warning dialog is displayed which incorrectly informs the user that unblocking iTunes Music Sharing doesn’t affect the firewall’s
    security. Allowing iTunes Music Sharing or any other service through the firewall inherently affects security by exposing the service to
    remote entities. This update addresses the issue by refining the text in the warning dialog. Available for Mac OS X v10.4.11, Mac OS X Server v10.4.11.
  • CVE-2008-3636: A third-party driver provided with iTunes may trigger an integer overflow, and could allow a local user to obtain system privileges. Available for: Windows XP or Vista.
[Source: zdnet]

How to: Securing iPhone

Securing iPhoneThe iPhone has vulnerabilities. In the past, some have been very serious. Sometimes, Apple takes a very long time to get them fixed.

The security hiccups have done nothing to slow down the sales and usage of the device so it just might be a good idea to go the extra mile to secure the device and reduce your risk if your iPhone gets lost or stolen.

Wired’s how-to wiki offers some valuable instructions on security your iPhone:

If you have any other ideas/suggestions, enter them in the comments or, better yet, post them to Wired’s wiki.

[Source: zdnet]

Apple ships (long overdue) iPhone security patches

Apple ships (long overdue) iPhone security patchesFinally, after months of waiting, iPhone users finally get security fixes for a batch of known software vulnerabilities.

The latest iPhone 2.0 and iPod Touch 2.0 update patches at least 13 documented vulnerabilities, including several code execution holes in the Safari (mobile) Web browser. The Safari bug that won the CanSecWest Pwn2Own contest was also patched.

In all, Apple documents eight flaws affecting Safari and another three bugs in WebKit, the open-source browser engine that powers Safari.

[ SEE: Apple caught neglecting iPhone security ]

The update also patches a CFNetwork bug that could lead to spoofing attacks on iPhone and a kernel vulnerability that could cause denial-of-service conditions.

This Apple advisory spells out the risks:

CVE-2008-0050 - A malicious HTTPS proxy server may return arbitrary data to CFNetwork in a 502 Bad Gateway error, which could allow a secure website to be spoofed.

CVE-2008-0177 - An undetected failure condition exists in the handling of packets with an IPComp header. Sending a maliciously crafted
packet to a system configured to use IPSec or IPv6 may cause an unexpected device reset.

CVE-2008-1588 - When Safari displays the current URL in the address bar, Unicode ideographic spaces are rendered. This allows a maliciously crafted website to direct the user to a spoofed site that visually appears to be a legitimate domain.

CVE-2008-1589 - When Safari accesses a website that uses a self-signed or invalid certificate, it prompts the user to accept or reject the
certificate. If the user presses the menu button while at the prompt, then on the next visit to the site, the certificate is accepted with no prompt. This may lead to the disclosure of sensitive information.

CVE-2008-2303 - A signedness issue in Safari’s handling of JavaScript array indices may result in an out-of-bounds memory access. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2006-2783 - Safari ignores Unicode byte order mark sequences when parsing web pages. Certain websites and web content filters attempt to sanitize input by blocking specific HTML tags. This approach to filtering may be bypassed and lead to cross-site scripting when
encountering maliciously-crafted HTML tags containing byte order mark sequences.

CVE-2008-2307 - A memory corruption issue exists in WebKit’s handling of JavaScript arrays. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-2317 - A memory corruption issue exists in WebCore’s handling of style sheet elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2007-6284 - A memory consumption issue exists in the handling of XML documents containing invalid UTF-8 sequences, which may lead to a denial of service.

CVE-2008-1767 - A memory corruption issue exists in the libxslt library. Viewing a maliciously crafted HTML page may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-1590 - A memory corruption issue exists in JavaScriptCore’s handling of runtime garbage collection. Visiting a maliciously
crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-1025 - An issue exists in WebKit’s handling of URLs containing a colon character in the host name. Accessing a maliciously crafted URL may lead to a cross-site scripting attack.

CVE-2008-1026 - A heap buffer overflow exists in WebKit’s handling of JavaScript regular expressions. The issue may be triggered via
JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution. This is Charlie Miller’s Pwn2Own contest vulnerability.

* Image source: nerichards Flickr photostream (Creative Commons 2.0)

[Source: zdnet]