Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:BROWSER-HTMLSLTELT-DOS

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Multiple Web Browsers 'HTMLSelectElement' Object Denial of Service

Release Date

2012/12/17

Update Number

2211

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Multiple Web Browsers 'HTMLSelectElement' Object Denial of Service


This signature detects attempts to exploit a known vulnerability against Multiple Web Browsers. A successful attack can result in a denial-of-service condition.

Extended Description

WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.

Affected Products

  • apple iphone
  • apple iphone_os 1.0.0
  • apple iphone_os 1.0.1
  • apple iphone_os 1.0.2
  • apple iphone_os 1.1.0
  • apple iphone_os 1.1.1
  • apple iphone_os 1.1.2
  • apple iphone_os 1.1.3
  • apple iphone_os 1.1.4
  • apple iphone_os 1.1.5
  • apple iphone_os 2.0
  • apple iphone_os 2.0.0
  • apple iphone_os 2.0.1
  • apple iphone_os 2.0.2
  • apple iphone_os 2.1
  • apple iphone_os 2.1.1
  • apple iphone_os 2.2
  • apple iphone_os 2.2.1
  • apple ipod_touch
  • apple safari

References

  • BugTraq: 35446
  • CVE: CVE-2009-1692
  • CVE: CVE-2009-2535
  • CVE: CVE-2009-2536
  • CVE: CVE-2009-2537
  • CVE: CVE-2009-2538
  • CVE: CVE-2009-2539
  • CVE: CVE-2009-2540
  • CVE: CVE-2009-2541
  • CVE: CVE-2009-2542
  • CVE: CVE-2009-2575

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out