|Main Archive Page > Month Archives > full-disclosure-uk archives|
CVE-2008-2303 covers an integer overflow in the handling of indices in the "arguments" array in Apple Safari that affects iPhone, iPod and PC (Mac and Windows). It was fixed in Safari 3.2 for iPhone and iPod in July and for PC in November. More details here: http://support.apple.com/kb/HT3298
http:// <goog_1231173753359>skypher <goog_1231173753359>.com/
I have also created proof of concept code that shows potential exploitability and demonstrates how to use heap-spraying in Safari. AFAIK this is the first use of heap spraying in Safari, but I may be wrong. Heap spraying in Safari is not that different from other browsers, just backwards ;)
No, script-kiddies, it is not a working "insert download and execute code here" exploit - view source for the win!!
I have created a list of software vulnerabilities, including previously unreleased material, on my website: