Apple Safari for Windows Window.setTimeout Content Spoofing Vulnerability
BID:24457
Info
Apple Safari for Windows Window.setTimeout Content Spoofing Vulnerability
| Bugtraq ID: | 24457 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2391 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2007 12:00AM |
| Updated: | Jun 14 2007 08:59PM |
| Credit: | Robert Swiecki is credited with the discovery of this vulnerability. |
| Vulnerable: |
Apple Safari 3 Beta |
| Not Vulnerable: |
Apple Safari 3.0.1 Beta for Windows |
Discussion
Apple Safari for Windows Window.setTimeout Content Spoofing Vulnerability
Apple Safari 3 Beta for Windows is prone to a content-spoofing vulnerability that allows attackers to steal browser cookie data or to populate a vulnerable Safari browser window with arbitrary malicious content. During such an attack, the originating URL and window title reportedly still display the originating domain rather than the attacking domain.
This issue affects Safari 3.0 (522.11.3) on Windows 2003 SE SP2 and Windows XP SP2.
NOTE: Apple has released Safari 3.0.1 Beta for Windows.
Apple Safari 3 Beta for Windows is prone to a content-spoofing vulnerability that allows attackers to steal browser cookie data or to populate a vulnerable Safari browser window with arbitrary malicious content. During such an attack, the originating URL and window title reportedly still display the originating domain rather than the attacking domain.
This issue affects Safari 3.0 (522.11.3) on Windows 2003 SE SP2 and Windows XP SP2.
NOTE: Apple has released Safari 3.0.1 Beta for Windows.
Exploit / POC
Apple Safari for Windows Window.setTimeout Content Spoofing Vulnerability
Attackers can use a browser to exploit this issue.
The following URI demonstrates this issue:
http://alt.swiecki.net/safc.html
Attackers can use a browser to exploit this issue.
The following URI demonstrates this issue:
http://alt.swiecki.net/safc.html
Solution / Fix
Apple Safari for Windows Window.setTimeout Content Spoofing Vulnerability
Solution:
Apple has released an updated version of the software that addresses this issue. Please see the vendor advisories for more information.
Solution:
Apple has released an updated version of the software that addresses this issue. Please see the vendor advisories for more information.
References
Apple Safari for Windows Window.setTimeout Content Spoofing Vulnerability
References:
References:
- Safari Home Page (Apple)