CVE编号
CVE-2009-0945利用情况
暂无补丁情况
官方补丁披露时间
2009-05-14漏洞描述
WebKit中insertItemBefore方法中的数组索引错误,如3.2.3和4 Public Beta之前的Apple Safari,iPhone OS 1.0 through 2.2.1,iPod touch 1.1 through 2.2.1的iPhone OS,1.0.154.65之前的Google Chrome稳定版,以及可能的其他产品允许远程攻击者通过(1)SVGTransformList,(2)SVGStringList,(3)SVGNumberList,(4)SVGPathSegList,(5)SVGPointList ,或(6)SVGLengthList SVGList对象中包含的中的 negative index的SVGPathList数据结构的文档,触发内存损坏,从而执行任意代码。解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
http://code.google.com/p/chromium/issues/detail?id=9019 | |
http://googlechromereleases.blogspot.com/2009/05/stable-update-bug-fix.html | |
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html | |
http://lists.apple.com/archives/security-announce/2009/May/msg00000.html | |
http://lists.apple.com/archives/security-announce/2009/May/msg00001.html | |
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html | |
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html | |
http://secunia.com/advisories/35056 | |
http://secunia.com/advisories/35074 | |
http://secunia.com/advisories/35095 | |
http://secunia.com/advisories/35576 | |
http://secunia.com/advisories/35805 | |
http://secunia.com/advisories/36062 | |
http://secunia.com/advisories/36461 | |
http://secunia.com/advisories/36790 | |
http://secunia.com/advisories/37746 | |
http://secunia.com/advisories/43068 | |
http://support.apple.com/kb/HT3549 | |
http://support.apple.com/kb/HT3550 | |
http://support.apple.com/kb/HT3639 | |
http://www.debian.org/security/2009/dsa-1950 | |
http://www.redhat.com/support/errata/RHSA-2009-1130.html | |
http://www.securityfocus.com/archive/1/503594/100/0/threaded | |
http://www.securityfocus.com/bid/34924 | |
http://www.securitytracker.com/id?1022207 | |
http://www.ubuntu.com/usn/USN-822-1 | |
http://www.ubuntu.com/usn/USN-836-1 | |
http://www.ubuntu.com/usn/USN-857-1 | |
http://www.us-cert.gov/cas/techalerts/TA09-133A.html | |
http://www.vupen.com/english/advisories/2009/1297 | |
http://www.vupen.com/english/advisories/2009/1298 | |
http://www.vupen.com/english/advisories/2009/1321 | |
http://www.vupen.com/english/advisories/2009/1621 | |
http://www.vupen.com/english/advisories/2011/0212 | |
http://www.zerodayinitiative.com/advisories/ZDI-09-022 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50477 | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova... | |
https://usn.ubuntu.com/823-1/ | |
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00303.html | |
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html | |
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | apple | safari | * |
Up to (including) 3.2.2 |
|||||
运行在以下环境 | |||||||||
应用 | apple | safari | 0.8 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 0.9 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0.0b1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0.0b2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.0.3 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.1.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.1.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2.3 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2.4 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.2.5 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.3 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.3.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.3.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 1.3.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2.0.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2.0.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2.0.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2.0.3 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 2.0.4 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.0.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.0.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.0.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.0.3 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.0.4 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.1.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.1.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.1.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.2 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.2.0 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 3.2.1 | - | |||||
运行在以下环境 | |||||||||
应用 | apple | safari | 4.0 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.4.11 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.0 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.1 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.2 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.3 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.4 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.5 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x | 10.5.6 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.4.11 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.5.0 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.5.1 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.5.2 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.5.3 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.5.4 | - | |||||
运行在以下环境 | |||||||||
系统 | apple | mac_os_x_server | 10.5.6 | - | |||||
运行在以下环境 | |||||||||
系统 | centos_5 | kdegraphics | * |
Up to (excluding) 3.5.4-13.el5_3 |
|||||
运行在以下环境 | |||||||||
系统 | debian_4.0 | kdegraphics | * |
Up to (excluding) 4:3.5.5-3etch4 |
|||||
运行在以下环境 | |||||||||
系统 | debian_5.0 | kdegraphics | * |
Up to (excluding) 1.0.1-4+lenny2 |
|||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_vista | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_xp | * | - | |||||
运行在以下环境 | |||||||||
系统 | redhat_5 | kdegraphics | * |
Up to (excluding) 7:3.5.4-13.el5_3 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12 | libqt4 | * |
Up to (excluding) 4.8.6-2 |
|||||
- 攻击路径 远程
- 攻击复杂度 容易
- 权限要求 无需权限
- 影响范围 全局影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 数据泄露
- 数据完整性 传输被破坏
- 服务器危害 服务器失陷
- 全网数量 N/A
还没有评论,来说两句吧...