PT-2009-2830 · Microsoft+1 · Windows Vista+3
Billy Rios
+2
·
Publicado
2009-02-12
·
Atualizado
2009-08-19
·
CVE-2009-0137
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Safari versions in Apple Mac OS X 10.4.11 and 10.5.6
Safari versions in Windows XP and Vista
Description
The issue is related to input validation problems, allowing remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed URL.
Recommendations
For Safari versions in Apple Mac OS X 10.4.11 and 10.5.6: update to a version with improved input validation.
For Safari versions in Windows XP and Vista: update to a version with improved input validation.
As a temporary workaround, consider restricting the use of feed URLs to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Macos X
Safari
Windows Vista
Windows Xp