PT-2009-2830 · Microsoft+1 · Windows Vista+3

Billy Rios

+2

·

Publicado

2009-02-12

·

Atualizado

2009-08-19

·

CVE-2009-0137

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari versions in Apple Mac OS X 10.4.11 and 10.5.6 Safari versions in Windows XP and Vista
Description The issue is related to input validation problems, allowing remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed URL.
Recommendations For Safari versions in Apple Mac OS X 10.4.11 and 10.5.6: update to a version with improved input validation. For Safari versions in Windows XP and Vista: update to a version with improved input validation. As a temporary workaround, consider restricting the use of feed URLs to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0137

Produtos afetados

Macos X
Safari
Windows Vista
Windows Xp