Safari < 4.0.2 Multiple Vulnerabilities
High Log Correlation Engine Plugin ID 801004
SynopsisThe remote host is vulnerable to multiple attack vectors.
DescriptionThe version of Safari installed on the remote host is earlier than 4.0.2. Such versions are potentially affected by two issues :
- A vulnerability in WebKit's handling of parent and top objects may allow for cross-site scripting attacks. (CVE-2009-1724)
- A memory corruption in WebKit's handling of numeric character references could lead to a crash or arbitrary code execution. (CVE-2009-1725)
SolutionUpgrade to Safari 4.0.2 or later.