Mac OS X : Safari < 6.0.5 Multiple Vulnerabilities

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote host contains a web browser that is affected by several
vulnerabilities.

Description :

The version of Safari installed on the remote Mac OS X 10.7 or 10.8
host is earlier than 6.0.5. It is, therefore, potentially affected by
several issues :

- Multiple memory corruption vulnerabilities exist in
WebKit that could lead to unexpected program termination
or arbitrary code execution. (CVE-2013-0879 /
CVE-2013-0991 / CVE-2013-0992 / CVE-2013-0993 /
CVE-2013-0994 / CVE-2013-0995 / CVE-2013-0996 /
CVE-2013-0997 / CVE-2013-0998 / CVE-2013-0999 /
CVE-2013-1000 / CVE-2013-1001 / CVE-2013-1002 /
CVE-2013-1003 / CVE-2013-1004 / CVE-2013-1005 /
CVE-2013-1006 / CVE-2013-1007 / CVE-2013-1008 /
CVE-2013-1009 / CVE-2013-1010 / CVE-2013-1011 /
CVE-2013-1023)

- A cross-site scripting issue exists in WebKit's handling
of iframes. (CVE-2013-1012)

- A cross-site scripting issue exists in WebKit's handling
of copied and pasted data in HTML documents.
(CVE-2013-0926)

- In rewriting URLs to prevent cross-site scripting
attacks, XSS Auditor could be abused, leading to
malicious alteration of the behavior of a form
submission. (CVE-2013-1013)

See also :

http://www.zerodayinitiative.com/advisories/ZDI-13-107/
http://www.zerodayinitiative.com/advisories/ZDI-13-108/
http://www.zerodayinitiative.com/advisories/ZDI-13-109/
http://support.apple.com/kb/HT5785
http://lists.apple.com/archives/security-announce/2013/Jun/msg00001.html
http://www.securityfocus.com/archive/1/526807/30/0/threaded

Solution :

Upgrade to Safari 6.0.5 or later.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.0
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false