Mac OS X : Apple Safari < 4.0.2

This script is Copyright (C) 2009-2015 Tenable Network Security, Inc.

Synopsis :

The remote host contains a web browser that is affected by several

Description :

The version of Apple Safari installed on the remote Mac OS X host is
earlier than 4.0.2 As such, it is potentially affected by two issues :

- A vulnerability in WebKit's handling of parent and top
objects may allow for cross-site scripting attacks.

- A memory corruption issue in WebKit's handling of
numeric character references could lead to a crash or
arbitrary code execution. (CVE-2009-1725)

See also :

Solution :

Upgrade to Apple Safari 4.0.2 or later.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false

Family: MacOS X Local Security Checks

Nessus Plugin ID: 39768 (macosx_Safari4_0_2.nasl)

Bugtraq ID: 35441

CVE ID: CVE-2009-1724