PT-2009-5199 · Apple · Webcore+2

Jan Lieskovsky

·

Published

2009-11-13

·

Updated

2017-08-17

·

CVE-2009-2841

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Safari versions prior to 4.0.4
Description The issue concerns the HTMLMediaElement::loadResource function in WebCore in WebKit, which does not perform the expected callbacks for HTML 5 media elements with external URLs for media resources. This allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document. An example of exploitation is through an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality.
Recommendations For Apple Safari versions prior to 4.0.4, update to version 4.0.4 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-2841

Affected Products

Safari
Webcore
Webkit