Apple Safari for Windows IDN URL Bar Spoofing Vulnerability
BID:24636
Info
Apple Safari for Windows IDN URL Bar Spoofing Vulnerability
| Bugtraq ID: | 24636 |
| Class: | Design Error |
| CVE: |
CVE-2007-3742 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2007 12:00AM |
| Updated: | Aug 01 2007 12:45PM |
| Credit: | Robert Swiecki reported this issue. |
| Vulnerable: |
Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple iPhone 1 |
| Not Vulnerable: |
Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple iPhone 1.0.1 |
Discussion
Apple Safari for Windows IDN URL Bar Spoofing Vulnerability
Apple Safari is prone to a vulnerability that permits attackers to spoof URL bar content.
Attackers may exploit this vulnerability via a malicious webpage to spoof the contents and origin of a page that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
This issue affects Apple Safari 3.0.2 for Windows; other versions may also be affected.
The iPhone is reported to be affected in the APPLE-SA-2007-07-31 iPhone v1.0.1 Update security advisory.
Apple Safari is prone to a vulnerability that permits attackers to spoof URL bar content.
Attackers may exploit this vulnerability via a malicious webpage to spoof the contents and origin of a page that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing.
This issue affects Apple Safari 3.0.2 for Windows; other versions may also be affected.
The iPhone is reported to be affected in the APPLE-SA-2007-07-31 iPhone v1.0.1 Update security advisory.
Exploit / POC
Apple Safari for Windows IDN URL Bar Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to visit a maliciously crafted webpage.
A sample URI has been provided:
http://alt.swiecki.net/idn.png
To exploit this issue, an attacker must entice an unsuspecting user to visit a maliciously crafted webpage.
A sample URI has been provided:
http://alt.swiecki.net/idn.png
Solution / Fix
Apple Safari for Windows IDN URL Bar Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Apple security advisory APPLE-SA-2007-07-31 iPhone v1.0.1 Update is available; please see the reference section for details.
It should be noted that this update is only available through iTunes and it will not be available through the Software Update application or through the Apple Downloads site. The update can be automatically detected and downloaded by iTunes. The user will be asked to install the update when iPhone is docked.
Apple has also released Safari 3 Beta Update 3.0.3 to address this issue. Please see references for more information
Apple Safari 3.0.2 Beta
Apple Safari 3.0.2 Beta for Windows
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Apple security advisory APPLE-SA-2007-07-31 iPhone v1.0.1 Update is available; please see the reference section for details.
It should be noted that this update is only available through iTunes and it will not be available through the Software Update application or through the Apple Downloads site. The update can be automatically detected and downloaded by iTunes. The user will be asked to install the update when iPhone is docked.
Apple has also released Safari 3 Beta Update 3.0.3 to address this issue. Please see references for more information
Apple Safari 3.0.2 Beta
-
Apple Safari3Beta.dmg
For Mac OS X
http://www.apple.com/safari/download/
Apple Safari 3.0.2 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari+QuickTime for Windows XP or Vista
http://www.apple.com/safari/download/
References
Apple Safari for Windows IDN URL Bar Spoofing Vulnerability
References:
References: