Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Safari < 6.2.1 / 7.1.1 / 8.0.1 Multiple Vulnerabilities

High

Synopsis

The remote host is missing a critical Safari patch update.

Description

According to its banner, the remote Safari browser is missing a security update to Webkit. Safari is bundled with Apple WebKit. Apple WebKit is affected by the following vulnerabilities :

- There is a 'use-after-free' vulnerability which can allow remote attackers to execute arbitrary code through crafted page objects within HTML. (CVE-2014-4459) - There is a policy bypass flaw which can allow remote attackers to bypass the 'Same Origin Policy' via Cascading Style Sheets. (CVE-2014-4465)

Solution

Upgrade to Safari 6.2.1 / 7.1.1 / 8.0.1 or later.