Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability
BID:11469
Info
Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability
| Bugtraq ID: | 11469 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-1122 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery is credited to Secunia. |
| Vulnerable: |
Apple Safari 1.2.3 |
| Not Vulnerable: | |
Discussion
Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability
Apple Safari is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.
Apple Safari 1.2.3 (v125.9) is reported vulnerable to this issue. It is likely that other versions are affected as well.
Apple Safari is reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.
Apple Safari 1.2.3 (v125.9) is reported vulnerable to this issue. It is likely that other versions are affected as well.
Exploit / POC
Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
Solution / Fix
Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability
Solution:
Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. Please see the referenced advisory for more information.
Apple Safari 1.2.3
Solution:
Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. Please see the referenced advisory for more information.
Apple Safari 1.2.3
-
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg
References
Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability
References:
References:
- Safari Dialog Box Spoofing Vulnerability (Secunia)
- Safari Homepage (Apple)