PT-2015-3112 · Apple · Safari+2

Jonathan Metzman

+1

·

Publicado

2015-12-11

·

Atualizado

2016-12-07

·

CVE-2015-7050

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Safari versions prior to 9.0.2 iOS versions prior to 9.2
Description The issue is related to the misparsing of content extensions in WebKit, which can allow remote attackers to obtain sensitive browsing-history information via a crafted web site. This is due to a lack of protection for service data. An attacker can exploit this issue to gain access to browsing history using a specially formed web site.
Recommendations For Safari versions prior to 9.0.2, update to version 9.0.2 or later to resolve the issue. For iOS versions prior to 9.2, update to version 9.2 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00322
CVE-2015-7050

Produtos afetados

Safari
Webkit
Ios