Rule

--
Sid
3-16319

--
Summary:
This event is generated when an attempt is made to exploit a known vulnerability in Safari.

--
Impact:
Denial of Service. Information disclosure. Loss of integrity. Complete admin access.

--
Detailed Information:
Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, aka a "Carpet Bomb," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because of certain behavior of the Windows desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.  NOTE: Microsoft describes the issue on the Windows platform as "a blended threat that allows remote code execution."

--
Affected Systems:
Apple Safari 3.0
Apple Safari 3.0
Apple Safari 3.0.1
Apple Safari 3.0.1
Apple Safari 3.0.2
Apple Safari 3.0.2
Apple Safari 3.0.3
Apple Safari 3.0.3
Apple Safari 3.0.4_beta
Apple Safari 3.0.4_beta
Apple Safari 3.1
Apple Safari 3.1.1

--
Attack Scenarios:


--
Ease of Attack:
Simple. Exploits exist.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Upgrade to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

--
Contributors:
Sourcefire Vulnerability Research Team
This document was generated from data supplied by the National Vulnerability Database. A product of the National Institute of Standards and Technology.
For more information see http://nvd.nist.gov/

--
Additional References:

NIST CVE-2008-2540:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2540
  
--
