RULE(RULE ID:333366)

Rule General Information
Release Date: 2021-04-01
Rule Name: WebKitGTK 2.1.2 Heap based Buffer Overflow Vulnerability (CVE-2014-1303)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, Others
Reference: http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html
http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html
http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html
http://twitter.com/thezdi/statuses/444157530139136000
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://support.apple.com/kb/HT6181