PT-2016-2280 · Apple · Webkit+2
Takeshi Terada
·
Publicado
2016-06-19
·
Atualizado
2017-09-01
·
CVE-2016-1864
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 9.1
iOS versions prior to 9.3
Description
The issue is related to the lack of protection for service data in the WebKit component's XSS auditor. This allows a remote attacker to obtain sensitive information using a specially crafted URL. The problem arises from the improper handling of redirects in block mode.
Recommendations
For Safari versions prior to 9.1, update to version 9.1 or later to resolve the issue.
For iOS versions prior to 9.3, update to version 9.3 or later to resolve the issue.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Safari
Webkit
Ios