A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in WebKit. When nesting regular expressions with large repetitions, a heap overflow occurs resulting in a condition allowing the execution of arbitrary code.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65589/ZDI-08-022.txt
Source: https://packetstormsecurity.com/files/65589/Zero-Day-Initiative-Advisory-08-022.html

