A memory corruption flaw exists in Apple Safari. The WebKit component fails to sanitize certain unspecified user-supplied input, resulting in memory corruption. Through vectors related to iTunes Store browsing, a man-in-the-middle attacker can execute arbitrary code.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Third-Party Solution,
Solution Unknown
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
OSVDB is not currently aware of a solution for this vulnerability.
Upgrade to Apple Safari version 5.0.4 or higher, as it has been reported to address this vulnerability. An upgrade is required as there is no known workaround.