PT-2009-2830 · Microsoft+1 · Windows Vista+3
Billy Rios
+2
·
Published
2009-02-12
·
Updated
2009-08-19
·
CVE-2009-0137
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Safari versions in Apple Mac OS X 10.4.11 and 10.5.6
Safari versions in Windows XP and Vista
Description
The issue is related to input validation problems, allowing remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed URL.
Recommendations
For Safari versions in Apple Mac OS X 10.4.11 and 10.5.6: update to a version with improved input validation.
For Safari versions in Windows XP and Vista: update to a version with improved input validation.
As a temporary workaround, consider restricting the use of feed URLs to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Macos X
Safari
Windows Vista
Windows Xp