Mac OS X : Safari < 6.1.5 / 7.0.5 Multiple Vulnerabilities

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote host contains a web browser that is affected by multiple
vulnerabilities.

Description :

The version of Safari installed on the remote Mac OS X host is a
version prior to 6.1.5 or 7.0.5. It is, therefore, affected by the
following vulnerabilities :

- Multiple memory corruption vulnerabilities exist in
WebKit that could lead to unexpected program
termination or arbitrary code execution.
(CVE-2014-1325, CVE-2014-1340, CVE-2014-1362,
CVE-2014-1363, CVE-2014-1364, CVE-2014-1365,
CVE-2014-1366, CVE-2014-1367, CVE-2014-1368,
CVE-2014-1382)

- An error exists in WebKit related to domains in URLs
and encoding that could allow spoofing attacks.
(CVE-2014-1345)

- An error exists in WebKit related to handling URLs
being dragged between windows that could allow
disclosure of local file content. (CVE-2014-1369)

See also :

http://support.apple.com/kb/HT6293
http://www.securityfocus.com/archive/1/532599/30/0/threaded

Solution :

Upgrade to Safari 6.1.5 / 7.0.5 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false