Safari/WebCore HTTP Content Filtering Bypass Vulnerability
BID:10999
Info
Safari/WebCore HTTP Content Filtering Bypass Vulnerability
| Bugtraq ID: | 10999 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2004 12:00AM |
| Updated: | Aug 23 2004 12:00AM |
| Credit: | fukami <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Apple Safari 1.1 Apple Safari 1.0 |
| Not Vulnerable: | |
Discussion
Safari/WebCore HTTP Content Filtering Bypass Vulnerability
It is reported that Safari and WebCore contain a vulnerability that may allow users to bypass access restrictions or content filters.
This vulnerability may allow users to bypass access restrictions that are in place for HTML documents. It may also allow HTMl documents to bypass inline content filters, potentially allowing malicious or inappropriate content to pass the filtering engine.
It is reported that Safari and WebCore contain a vulnerability that may allow users to bypass access restrictions or content filters.
This vulnerability may allow users to bypass access restrictions that are in place for HTML documents. It may also allow HTMl documents to bypass inline content filters, potentially allowing malicious or inappropriate content to pass the filtering engine.
Exploit / POC
Safari/WebCore HTTP Content Filtering Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Safari/WebCore HTTP Content Filtering Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Safari/WebCore HTTP Content Filtering Bypass Vulnerability
References:
References:
- Consistency of Media Types and Message Contents (W3C)
- RFC 2616 - Hypertext Transfer Protocol -- HTTP/1.1 (RFC)
- Safari Homepage (Apple)
- Safari/WebCore Content Sniffing (fukami
) - WebCore Home Page (Apple)