PT-2010-5083 · Apple · Safari
Jason Hullinger
·
Published
2010-11-16
·
Updated
2010-11-17
·
CVE-2010-3796
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 10.6.5 in Mac OS X 10.5.8 and 10.6.x
Description
The issue allows remote attackers to obtain sensitive information by using a feed: URL containing a Java applet that performs DOM modifications, as Safari does not block Java applets in an RSS feed.
Recommendations
For Safari in Mac OS X 10.5.8 and 10.6.x before 10.6.5, consider disabling Java applets in RSS feeds until a patch is available.
Restrict access to RSS feeds that may contain malicious Java applets to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safari