Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability
BID:24599
Info
Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability
| Bugtraq ID: | 24599 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-2400 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2007 12:00AM |
| Updated: | Aug 01 2007 06:55PM |
| Credit: | Lawrence Lai, Stan Switzer, Ed Rowe of Adobe Systems, Inc disclosed this vulnerability. |
| Vulnerable: |
Apple Safari 3.0.1 Beta for Windows Apple Safari 3.0.1 Beta Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple iPhone 1 |
| Not Vulnerable: |
Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta |
Discussion
Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability
Apple Safari is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain JavaScript restrictions.
Exploiting this issue may allow attackers to access locations that a user visits, even if those locations are in a different domain than the attacker's site. The most common manifestation of this condition would typically be in blogs or forums. Attackers may be able to access potentially sensitive information that would aid in phishing attacks.
This issue affects versions prior to Safari 3 Beta Update 3.0.2
Apple Safari is prone to an information-disclosure vulnerability because it fails to properly enforce cross-domain JavaScript restrictions.
Exploiting this issue may allow attackers to access locations that a user visits, even if those locations are in a different domain than the attacker's site. The most common manifestation of this condition would typically be in blogs or forums. Attackers may be able to access potentially sensitive information that would aid in phishing attacks.
This issue affects versions prior to Safari 3 Beta Update 3.0.2
Exploit / POC
Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability
Attackers use standard HTML design utilities and webserver applications to exploit this issue.
Attackers use standard HTML design utilities and webserver applications to exploit this issue.
Solution / Fix
Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability
Solution:
Apple security advisories and fixes are available:
- APPLE-SA-2007-06-22
- APPLE-SA-2007-07-31 iPhone v1.0.1 Update
Please see the references for details.
Note that the iPhone update is available only through iTunes; it will not be available through the Software Update application or the Apple Downloads site. The update is automatically detected and downloaded by iTunes -- the user will be asked to install the update when the iPhone is docked.
Apple Mac OS X Server 10.4.10
Apple Mac OS X Server 10.4.9
Apple Safari 3.0.1 Beta for Windows
Solution:
Apple security advisories and fixes are available:
- APPLE-SA-2007-06-22
- APPLE-SA-2007-07-31 iPhone v1.0.1 Update
Please see the references for details.
Note that the iPhone update is available only through iTunes; it will not be available through the Software Update application or the Apple Downloads site. The update is automatically detected and downloaded by iTunes -- the user will be asked to install the update when the iPhone is docked.
Apple Mac OS X Server 10.4.10
-
Apple Safari302Beta.dmg
http://www.apple.com/safari/download/Safari302Beta.dmg
Apple Mac OS X Server 10.4.9
-
Apple Safari302Beta.dmg
http://www.apple.com/safari/download/Safari302Beta.dmg
Apple Safari 3.0.1 Beta for Windows
-
Apple Safari302Beta.dmg
http://www.apple.com/safari/download/Safari302Beta.dmg
References
Apple Safari Cross-Domain Race Condition Information Disclosure Vulnerability
References:
References: