[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Apple Safari for Windows (4.0.2-4.0.5, 5.0-5.0.2) Math.random() predictability
- To: "bugtraq@xxxxxxxxxxxxxxxxx" <bugtraq@xxxxxxxxxxxxxxxxx>
- Subject: Apple Safari for Windows (4.0.2-4.0.5, 5.0-5.0.2) Math.random() predictability
- From: Amit Klein <amit.klein@xxxxxxxxxxxx>
- Date: Sun, 21 Nov 2010 04:33:45 -0600
Hi list
Earlier this year, Trusteer discovered a vulnerability in Apple Safari for
Windows (versions 4.0.2-4.0.5 and 5.0-5.0.2). The issue is in the Javascript
Math.random function, which is implemented in Safari via its WebKit core.
Trusteer reported this vulnerability to Apple and to WebKit.org. Today Apple
released a fix to this vulnerability - as Safari 5.0.3
(http://support.apple.com/kb/HT1222, http://support.apple.com/kb/HT4455).
For more details, please read the full report:
http://www.trusteer.com/sites/default/files/Temporary_User_Tracking_in_Safari_for_Windows.pdf
Thanks,
-Amit
Amit Klein, CTO, Trusteer