Short Name |
HTTP:STC:SAFARI-IE-RCE
|
Severity |
High
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Apple Safari for Windows and Internet Explorer Combined Code Execution
|
Release Date |
2010/10/05
|
Update Number |
1785
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: Apple Safari for Windows and Internet Explorer Combined Code Execution
This signature detects attempts to exploit a known vulnerability against Apple Safari and Internet Explorer for Windows. A successful attack can lead to arbitrary code execution.
Extended Description
A vulnerability in Apple Safari on the Microsoft Windows operating system stems from a combination of security issues in Safari and all versions of Windows XP and Vista that will allow executables to be downloaded to a user's computer and run without prompting.
A vulnerability in Safari, known as the 'carpet-bombing' issue reported by Nitesh Dhanjani, allows an attacker to silently place malicious DLL files on a victim's computer. A problem in Internet Explorer, reported in December of 2006 by Aviv Raff, can then be used to run those malicious DLLs.
An attacker can exploit this issue by tricking a victim into visiting a malicious page with Safari; the malicious files will run when the victim starts Internet Explorer.
Affected Products
- Apple Safari 3.0.1 Beta For Windows
- Apple Safari 3.0.2 Beta For Windows
- Apple Safari 3.0.3 Beta For Windows
- Apple Safari 3.0.4 Beta For Windows
- Apple Safari 3.1
- Apple Safari 3.1.1
- Apple Safari 3.1.1 For Windows
- Apple Safari 3.1 For Windows
- Apple Safari 3 Beta For Windows
- Avaya Messaging Application Server MM 1.1
- Avaya Messaging Application Server MM 2.0
- Avaya Messaging Application Server MM 3.0
- Avaya Messaging Application Server MM 3.1
- Avaya Messaging Application Server
- Microsoft Internet Explorer 7.0
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP3
- Microsoft Windows 2000 Advanced Server SP4
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP3
- Microsoft Windows 2000 Datacenter Server SP4
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP4
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP3
- Microsoft Windows 2000 Server SP4
- Microsoft Windows 2000 Server
- Microsoft Windows Server 2003 SP1
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Server 2003 Datacenter Edition SP1
- Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1
- Microsoft Windows Server 2003 Datacenter Edition
- Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
- Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1
- Microsoft Windows Server 2003 Datacenter Edition Itanium
- Microsoft Windows Server 2003 Enterprise Edition SP1
- Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1
- Microsoft Windows Server 2003 Enterprise Edition
- Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
- Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1
- Microsoft Windows Server 2003 Enterprise Edition Itanium
- Microsoft Windows Server 2003 Enterprise x64 Edition SP2
- Microsoft Windows Server 2003 Enterprise x64 Edition
- Microsoft Windows Server 2003 Itanium SP1
- Microsoft Windows Server 2003 Itanium SP2
- Microsoft Windows Server 2003 Itanium
- Microsoft Windows Server 2003 Standard Edition SP1
- Microsoft Windows Server 2003 Standard Edition SP1 Beta 1
- Microsoft Windows Server 2003 Standard Edition SP2
- Microsoft Windows Server 2003 Standard Edition
- Microsoft Windows Server 2003 Web Edition SP1
- Microsoft Windows Server 2003 Web Edition SP2
- Microsoft Windows Server 2003 Web Edition
- Microsoft Windows Server 2003 x64 SP1
- Microsoft Windows Server 2003 x64 SP2
- Microsoft Windows Server 2008 Datacenter Edition Release Candidate
- Microsoft Windows Server 2008 Datacenter Edition
- Microsoft Windows Server 2008 Enterprise Edition Release Candidate
- Microsoft Windows Server 2008 Enterprise Edition
- Microsoft Windows Server 2008 for 32-bit Systems
- Microsoft Windows Server 2008 for Itanium-based Systems
- Microsoft Windows Server 2008 for x64-based Systems
- Microsoft Windows Server 2008 Standard Edition Release Candidate
- Microsoft Windows Server 2008 Standard Edition
- Microsoft Windows Vista Business
- Microsoft Windows Vista Business SP1
- Microsoft Windows Vista Enterprise
- Microsoft Windows Vista Enterprise SP1
- Microsoft Windows Vista Home Basic
- Microsoft Windows Vista Home Basic SP1
- Microsoft Windows Vista Home Premium
- Microsoft Windows Vista Home Premium SP1
- Microsoft Windows Vista SP1
- Microsoft Windows Vista Ultimate
- Microsoft Windows Vista Ultimate SP1
- Microsoft Windows Vista
- Microsoft Windows Vista Business 64-bit edition SP1
- Microsoft Windows Vista Business 64-bit edition
- Microsoft Windows Vista Enterprise 64-bit edition SP1
- Microsoft Windows Vista Enterprise 64-bit edition
- Microsoft Windows Vista Home Basic 64-bit edition SP1
- Microsoft Windows Vista Home Basic 64-bit edition
- Microsoft Windows Vista Home Premium 64-bit edition SP1
- Microsoft Windows Vista Home Premium 64-bit edition
- Microsoft Windows Vista Ultimate 64-bit edition SP1
- Microsoft Windows Vista Ultimate 64-bit edition
- Microsoft Windows Vista x64 Edition SP1
- Microsoft Windows Vista x64 Edition
- Microsoft Windows XP 64-bit Edition SP1
- Microsoft Windows XP 64-bit Edition
- Microsoft Windows XP 64-bit Edition Version 2003 SP1
- Microsoft Windows XP 64-bit Edition Version 2003
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home SP2
- Microsoft Windows XP Home SP3
- Microsoft Windows XP Home
- Microsoft Windows XP Media Center Edition SP1
- Microsoft Windows XP Media Center Edition SP2
- Microsoft Windows XP Media Center Edition SP3
- Microsoft Windows XP Media Center Edition
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional SP2
- Microsoft Windows XP Professional SP3
- Microsoft Windows XP Professional
- Microsoft Windows XP Professional x64 Edition SP2
- Microsoft Windows XP Professional x64 Edition SP3
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows XP Tablet PC Edition SP1
- Microsoft Windows XP Tablet PC Edition SP2
- Microsoft Windows XP Tablet PC Edition SP3
- Microsoft Windows XP Tablet PC Edition
- Nortel Networks CallPilot 1002Rp
- Nortel Networks CallPilot 1005R
- Nortel Networks CallPilot 201I
- Nortel Networks CallPilot 600R
- Nortel Networks CallPilot 703T
- Nortel Networks Contact Center
- Nortel Networks Contact Center Administration
- Nortel Networks Contact Center Express
- Nortel Networks Contact Center Manager
- Nortel Networks Contact Center Manager Server
- Nortel Networks Contact Center Multimedia
References