Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Apple Safari Large JavaScript Array Handling Denial Of Service Vulnerability

Mar 9, 2004 1:30PM PST

Apple Safari Web Browser is reported to be prone to a security vulnerability related to handling of large JavaScript arrays (with 99999999999999999999999 or 0x23000000 elements). By declaring such an array and then attempting to access it, it may be possible to cause a browser crash.

This issue is likely due to memory corruption but it is not known if it could be further exploitable to execute arbitrary code.

vulnerable Apple Safari Beta 2
Apple Safari 1.0
Apple Safari 1.1

http://www.securityfocus.com/bid/9815/info/

Discussion is locked