.:[ packet storm ]:.
                         
security in numbers
security in numbers

 ///  File Name:ZDI-10-029.txt
Description:
Zero Day Initiative Advisory 10-029 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the WebCore's HTMLObjectElement::renderFallBackContent() method. By rewriting an HTML element via the document's innerHTML() method a memory corruption occurs resulting from a call-after-free. This can be leveraged to execute arbitrary code under the context of the current user.
Author:TippingPoint
Homepage:http://www.zerodayinitiative.com/
File Size:2730
Related CVE(s):CVE-2010-0050
Last Modified:Mar 15 22:50:04 2010
MD5 Checksum:8ead72db8cf3df3d033a75fb0998dc6b

 .:. Back