Mac OS X : Safari < 6.0.3 Multiple Vulnerabilities

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote host contains a web browser that is affected by several
vulnerabilities.

Description :

The version of Safari installed on the remote Mac OS X 10.7 or 10.8
host is earlier than 6.0.3. It is, therefore, potentially affected
by several issues :

- Multiple memory corruption vulnerabilities exist in
WebKit that could lead to unexpected program termination
or arbitrary code execution. (CVE-2012-2824 /
CVE-2012-2857 / CVE-2013-0948 / CVE-2013-0949 /
CVE-2013-0950 / CVE-2013-0951 / CVE-2013-0952 /
CVE-2013-0953 / CVE-2013-0954 / CVE-2013-0955 /
CVE-2013-0956 / CVE-2013-0958 / CVE-2013-0959 /
CVE-2013-0960 / CVE-2013-0961)

- A cross-site scripting issue exists in WebKit's handling
of frame elements. (CVE-2012-2889)

- A cross-site scripting issue exists in WebKit's handling
of content pasted from a different origin.
(CVE-2013-0962)

See also :

http://support.apple.com/kb/HT5671
http://lists.apple.com/archives/security-announce/2013/Mar/msg00003.html
http://www.securityfocus.com/archive/1/526005/30/0/threaded

Solution :

Upgrade to Safari 6.0.3 or later.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.9
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false