[<prev] [next>] [day] [month] [year] [list]
Message-id: <6A1D9E79-849F-45F1-9079-46B3F33F7A44@lists.apple.com>
Date: Thu, 12 Sep 2013 13:43:56 -0700
From: Apple Product Security <product-security-noreply@...ts.apple.com>
To: "security-announce@...ts.apple.com" <security-announce@...ts.apple.com>
Subject: APPLE-SA-2013-09-12-2 Safari 5.1.10
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
APPLE-SA-2013-09-12-2 Safari 5.1.10
Safari 5.1.10 is now available and addresses the following:
JavaScriptCore
Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8
Impact: Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in
JavaScriptCore's JSArray::sort() method. These issues were addressed
through additional bounds checking.
CVE-ID
CVE-2012-3748 : Joost Pol and Daan Keuper of Certified Secure working
with HP TippingPoint's Zero Day Initiative
CVE-2013-0997 : Vitaliy Toropov working with HP's Zero Day Initiative
Safari 5.1.10 is available via the Apple Software Update
application, or Apple's Safari download site at:
http://support.apple.com/downloads/#safari
Safari for Mac OS X v10.6.8
The download file is named: Safari5.1.10SnowLeopardManual.dmg
Its SHA-1 digest is: 16fa66d8c8336688d983e1f125f773bb45fa3897
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org
iQIcBAEBAgAGBQJSMiO5AAoJEPefwLHPlZEwsPIP/1GjMQjOgt+4qhRakbgh4aT+
K69+4jlcSL3Rx9KRp1KuNSi7hrR4oad27KZwpRpS//PguSuhNnEokF5TOHiO+t+D
t4svsvwZqpYUZQCc1mXtW+l8rzMf87fXoWMItw4Sbf3bHrCozpfA4PKBQoMGH64J
uCKSYfZ163+KkL5vncYxFxwyH5QZUKS2fstglQRPhRZFuPcYsQXtn+8q4g3TLgBT
K1WPqSLoGEIKikHQpXexL496cafZTOgl147Qy2a/GHF5abrsOQ7/hxDtKOibYWlf
kVN53+Bl1ibWlw7Itu5rx30Q/l8zRiTCBjhZ0np9t4CAIGDfaMPQOWbBYcaE/dB2
geuAHXLMGSoWEF+DktmQCoq4eIXzyoZNsyUYWrOs597mTKwTHUgxnhQdOu+8DEiB
YNdvoKU6kMFUW8HhR4vSZmLJX9pJwgDvk1CW0f1oFrEhI5u4s+dM4tZKArdaQY/Z
CRWGxCiuCRZWn5kE7O6ClnW6qEels5c0r1IIOqm4B6iZ0xGpSOboHn4sgHyP52RZ
Tj/Yh618mYqHE16I5NwAMjRNIAXrrrMr2XtMxCWpxzR8NeEvlDmYgBpMh/Jggatw
Gds64YuNbQGrEOLe1Vaid/GgXDGOXGNnaz6zae+Da3Ep87R9gTFaXXbTs2Sl1quM
PLeozUvV/8aOBrng0blU
=ZzCa
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists