Apple Safari Cross-Domain Frame Loading Vulnerability
BID:11140
Info
Apple Safari Cross-Domain Frame Loading Vulnerability
| Bugtraq ID: | 11140 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0720 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | This issue was reported by Gary McKay. |
| Vulnerable: |
Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.2.8 |
| Not Vulnerable: | |
Discussion
Apple Safari Cross-Domain Frame Loading Vulnerability
Apple Safari is reported prone to a cross-domain frame loading vulnerability. It is reported that if the name of a frame rendered in a target site is known, then an attacker may potentially render arbitrary HTML in the frame of the target site.
An attacker may exploit this vulnerability to spoof an interface of a trusted web site. To exploit this vulnerability a victim will need to visit a website hosted by an attacker. The attackers site will then spawn a trusted site in a window, if exploited successfully; the attackers site will place data into the IFRAME of the trusted site. This vulnerability may aid in Phishing style attacks.
The version of Safari included in Apple Mac OS X versions 1.2.8, 10.3.4, and 10.3.5 is reported vulnerable to this issue.
Apple Safari is reported prone to a cross-domain frame loading vulnerability. It is reported that if the name of a frame rendered in a target site is known, then an attacker may potentially render arbitrary HTML in the frame of the target site.
An attacker may exploit this vulnerability to spoof an interface of a trusted web site. To exploit this vulnerability a victim will need to visit a website hosted by an attacker. The attackers site will then spawn a trusted site in a window, if exploited successfully; the attackers site will place data into the IFRAME of the trusted site. This vulnerability may aid in Phishing style attacks.
The version of Safari included in Apple Mac OS X versions 1.2.8, 10.3.4, and 10.3.5 is reported vulnerable to this issue.
Exploit / POC
Apple Safari Cross-Domain Frame Loading Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple Safari Cross-Domain Frame Loading Vulnerability
Solution:
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Apple has released advisory APPLE-SA-2004-09-13 along with Security Update 2004-09-07 v1.1 resolving non-security related issues that arose with the application of the first security update. Users are recommended to apply the latest security update. Please note that the fix links remain unchanged.
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.4
Apple Mac OS X 10.3.5
Apple Mac OS X Server 10.3.5
Solution:
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Apple has released advisory APPLE-SA-2004-09-13 along with Security Update 2004-09-07 v1.1 resolving non-security related issues that arose with the application of the first security update. Users are recommended to apply the latest security update. Please note that the fix links remain unchanged.
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-09-07JagClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04717&plat form=osx&method=sa/SecUpd2004-09-07JagClient.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpdSrvr2004-09-07Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04716&plat form=osx&method=sa/SecUpdSrvr2004-09-07Jag.dmg
Apple Mac OS X 10.3.4
-
Apple SecUpd2004-09-07PanClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04712&plat form=osx&method=sa/SecUpd2004-09-07PanClient.dmg
Apple Mac OS X Server 10.3.4
-
Apple SecUpdSrvr2004-09-07PanL.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04713&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanL.dmg
Apple Mac OS X 10.3.5
-
Apple SecUpd2004-09-07PanMClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04715&plat form=osx&method=sa/SecUpd2004-09-07PanMClient.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpdSrvr2004-09-07PanM.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04714&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanM.dmg
References
Apple Safari Cross-Domain Frame Loading Vulnerability
References:
References:
- Apple Security Announce Archive (Apple)
- Apple Security Updates (Apple)
- Safari Homepage (Apple)