Mac OS X : Safari < 6.1.4 / 7.0.4 Multiple Vulnerabilities

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote host contains a web browser that is affected by multiple
vulnerabilities.

Description :

The version of Safari installed on the remote Mac OS X host is a
version prior to 6.1.4 or 7.0.4. It is, therefore, potentially
affected by the following vulnerabilities :

- Multiple memory corruption vulnerabilities exist in
WebKit that could lead to unexpected program
termination or arbitrary code execution.
(CVE-2013-2875, CVE-2013-2927, CVE-2014-1323,
CVE-2014-1324, CVE-2014-1326, CVE-2014-1327,
CVE-2014-1329, CVE-2014-1330, CVE-2014-1331,
CVE-2014-1333, CVE-2014-1334, CVE-2014-1335,
CVE-2014-1336, CVE-2014-1337, CVE-2014-1338,
CVE-2014-1339, CVE-2014-1341, CVE-2014-1342,
CVE-2014-1343, CVE-2014-1344, CVE-2014-1731)

- An error exists related to unicode character handling
in URLs that could allow an attacker send an incorrect
'postMessage' origin that could allow a security bypass.
(CVE-2014-1346)

See also :

http://support.apple.com/kb/HT6254
http://www.securityfocus.com/archive/1/532186/30/0/threaded

Solution :

Upgrade to Safari 6.1.4 / 7.0.4 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false