Apple Safari for Windows Content and URLBar Spoofing Vulnerability
BID:24484
Info
Apple Safari for Windows Content and URLBar Spoofing Vulnerability
| Bugtraq ID: | 24484 |
| Class: | Design Error |
| CVE: |
CVE-2007-2398 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2007 12:00AM |
| Updated: | Apr 18 2008 12:28AM |
| Credit: | Robert Swiecki reported this issue. |
| Vulnerable: |
Apple Safari 3.0.1 Beta for Windows Apple Safari 3.1 |
| Not Vulnerable: |
Apple Safari 3.1.1 Apple Safari 3.0.2 Beta for Windows Apple Safari 2.0.4 |
Discussion
Apple Safari for Windows Content and URLBar Spoofing Vulnerability
Apple Safari 3.0.1 Beta for Windows is prone to a vulnerability that lets attackers spoof window titles and URL bars.
Attackers may exploit this vulnerability via a malicious webpage to spoof the contents and origin of a page that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Safari 3.0.1 (522.12.12) on Windows 2003 SE SP2 is reported vulnerable; other versions may also be affected.
Apple Safari 3.0.1 Beta for Windows is prone to a vulnerability that lets attackers spoof window titles and URL bars.
Attackers may exploit this vulnerability via a malicious webpage to spoof the contents and origin of a page that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
Safari 3.0.1 (522.12.12) on Windows 2003 SE SP2 is reported vulnerable; other versions may also be affected.
Exploit / POC
Apple Safari for Windows Content and URLBar Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to visit a maliciously crafted webpage.
The following URI demonstrates this issue:
http://alt.swiecki.net/saff.html
To exploit this issue, an attacker must entice an unsuspecting user to visit a maliciously crafted webpage.
The following URI demonstrates this issue:
http://alt.swiecki.net/saff.html
Solution / Fix
Apple Safari for Windows Content and URLBar Spoofing Vulnerability
Solution:
Apple security advisory APPLE-SA-2007-06-22 and fixes are available; please see the reference section for details.
The vendor reports this issue was re-introduced in Safari 3.1. Security advisory APPLE-SA-2008-04-16 is available with fixes.
Apple Safari 3.1
Apple Safari 3.0.1 Beta for Windows
Solution:
Apple security advisory APPLE-SA-2007-06-22 and fixes are available; please see the reference section for details.
The vendor reports this issue was re-introduced in Safari 3.1. Security advisory APPLE-SA-2008-04-16 is available with fixes.
Apple Safari 3.1
-
Apple Safari 3.1.1 for Leopard
Safari for Mac OS X v10.5.2
http://www.apple.com/safari/download/Safari311UpdLeo.dmg -
Apple Safari 3.1.1 Tiger
Safari for Mac OS X v10.4.11
http://www.apple.com/safari/download/Safari311UpdTiger.dmg -
Apple Safari 3.1.1 Windows QuickTime Setup
Safari+QuickTime for Windows XP or Vista
http://www.apple.com/safari/download/SafariQuickTimeSetup.exe -
Apple Safari 3.1.1 Windows Setup
Safari for Windows XP or Vista
http://www.apple.com/safari/download/SafariSetup.exe
Apple Safari 3.0.1 Beta for Windows
-
Apple SafariSetup.exe
Safari 3 Beta Update 3.0.2 for Windows XP or Vista
http://www.apple.com/safari/download/SafariSetup.exe
References
Apple Safari for Windows Content and URLBar Spoofing Vulnerability
References:
References:
- About the security content of Safari 3.1.1 (Apple)
- Safari Homepage (Apple)
- Re: [Full-disclosure] Apple Safari: urlbar/window title spoofing (Robert Swiecki)
- Re: [Full-disclosure] Apple Safari: urlbar/window title spoofing ("Mark Senior"
)