PT-2009-5199 · Apple · Webcore+2

Jan Lieskovsky

·

Publicado

2009-11-13

·

Atualizado

2017-08-17

·

CVE-2009-2841

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Safari versions prior to 4.0.4
Description The issue concerns the HTMLMediaElement::loadResource function in WebCore in WebKit, which does not perform the expected callbacks for HTML 5 media elements with external URLs for media resources. This allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document. An example of exploitation is through an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality.
Recommendations For Apple Safari versions prior to 4.0.4, update to version 4.0.4 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-2841

Produtos afetados

Safari
Webcore
Webkit