Safari < 5.1 多個弱點

high Nessus Plugin ID 55639

Synopsis

遠端主機包含一個受到數個弱點影響的網頁瀏覽器。

描述

遠端 Windows 主機上安裝的 Safari 版本比 5.1 舊。因此,其可能受到下列元件內的多個問題影響:

- CFNetwork
- ColorSync
- CoreFoundation
- CoreGraphics
- International Components for Unicode
- ImageIO
- libxslt
- libxml
- Safari
- WebKit

解決方案

升級至 Safari 5.1 或更新版本。

另請參閱

http://support.apple.com/kb/HT4808

http://lists.apple.com/archives/security-announce/2011/Jul/msg00002.html

Plugin 詳細資訊

嚴重性: High

ID: 55639

檔案名稱: safari_5_1.nasl

版本: 1.47

類型: local

代理程式: windows

系列: Windows

已發布: 2011/7/21

已更新: 2018/7/27

支持的傳感器: Nessus Agent

風險資訊

VPR

風險因素: High

分數: 7.4

CVSS v2

風險因素: High

基本分數: 9.3

時間分數: 7.7

媒介: AV:N/AC:M/Au:N/C:C/I:C/A:C

時間媒介: E:F/RL:OF/RC:C

弱點資訊

CPE: cpe:/a:apple:safari

必要的 KB 項目: SMB/Safari/FileVersion

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2011/7/20

弱點發布日期: 2010/7/26

惡意利用途徑

CANVAS (White_Phosphorus)

Core Impact

Metasploit (Apple Safari Webkit libxslt Arbitrary File Creation)

ExploitHub (EH-11-678)

參考資訊

CVE: CVE-2010-1383, CVE-2010-1420, CVE-2010-1823, CVE-2010-3829, CVE-2011-0164, CVE-2011-0195, CVE-2011-0200, CVE-2011-0201, CVE-2011-0202, CVE-2011-0204, CVE-2011-0206, CVE-2011-0214, CVE-2011-0215, CVE-2011-0216, CVE-2011-0217, CVE-2011-0218, CVE-2011-0219, CVE-2011-0221, CVE-2011-0222, CVE-2011-0223, CVE-2011-0225, CVE-2011-0232, CVE-2011-0233, CVE-2011-0234, CVE-2011-0235, CVE-2011-0237, CVE-2011-0238, CVE-2011-0240, CVE-2011-0241, CVE-2011-0242, CVE-2011-0244, CVE-2011-0253, CVE-2011-0254, CVE-2011-0255, CVE-2011-0981, CVE-2011-0983, CVE-2011-1107, CVE-2011-1109, CVE-2011-1114, CVE-2011-1115, CVE-2011-1117, CVE-2011-1121, CVE-2011-1188, CVE-2011-1190, CVE-2011-1203, CVE-2011-1204, CVE-2011-1288, CVE-2011-1293, CVE-2011-1295, CVE-2011-1296, CVE-2011-1449, CVE-2011-1451, CVE-2011-1453, CVE-2011-1457, CVE-2011-1462, CVE-2011-1774, CVE-2011-1797, CVE-2011-3443

BID: 43228, 46262, 46614, 46703, 46785, 47029, 47604, 47668, 48416, 48426, 48427, 48429, 48437, 48820, 48823, 48824, 48825, 48827, 48828, 48831, 48832, 48833, 48837, 48839, 48840, 48841, 48842, 48843, 48844, 48845, 48846, 48847, 48848, 48849, 48850, 48851, 48852, 48853, 48854, 48855, 48856, 48857, 48858, 48859, 48860

EDB-ID: 17575, 17993

MSVR: MSVR11-009