Mac OS X : Safari < 4.0.2

This script is Copyright (C) 2009-2012 Tenable Network Security, Inc.


Synopsis :

The remote host contains a web browser that is affected by several
vulnerabilities.

Description :

The version of Safari installed on the remote Mac OS X host is
earlier than 4.0.2 As such, it is potentially affected by two issues :

- A vulnerability in WebKit's handling of parent and top
objects may allow for cross-site scripting attacks.
(CVE-2009-1724)

- A memory corruption issue in WebKit's handling of
numeric character references could lead to a crash or
arbitrary code execution. (CVE-2009-1725)

See also :

http://support.apple.com/kb/HT3666
http://lists.apple.com/archives/security-announce/2009/Jul/msg00000.html
http://www.securityfocus.com/advisories/17297

Solution :

Upgrade to Safari 4.0.2 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: MacOS X Local Security Checks

Nessus Plugin ID: 39768 (macosx_Safari4_0_2.nasl)

Bugtraq ID: 35441
35607

CVE ID: CVE-2009-1724
CVE-2009-1725