Apple Safari Subframe Same Origin Policy Violation Vulnerability
BID:26911
Info
Apple Safari Subframe Same Origin Policy Violation Vulnerability
| Bugtraq ID: | 26911 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-5858 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | Jan 15 2008 09:58PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple Safari 3.0.1 Beta for Windows Apple Safari 3.0.1 Beta Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.5 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 |
| Not Vulnerable: |
Apple Safari 3.0.4 Beta for Windows Apple iPod Touch 1.1.3 Apple iPhone 1.1.3 |
Discussion
Apple Safari Subframe Same Origin Policy Violation Vulnerability
Apple Safari is prone to a vulnerability that allows attackers to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy for subframe access.
An attacker may create a malicious webpage that can access the properties of another domain. This may allow the attacker to obtain sensitive information or launch other attacks against a user of the browser.
Safari 3 for both Microsoft Windows and Apple Mac OS X platforms is vulnerable to this issue.
Apple Safari is prone to a vulnerability that allows attackers to violate the same-origin policy. This issue occurs because the application fails to properly enforce the same-origin policy for subframe access.
An attacker may create a malicious webpage that can access the properties of another domain. This may allow the attacker to obtain sensitive information or launch other attacks against a user of the browser.
Safari 3 for both Microsoft Windows and Apple Mac OS X platforms is vulnerable to this issue.
Exploit / POC
Apple Safari Subframe Same Origin Policy Violation Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple Safari Subframe Same Origin Policy Violation Vulnerability
Solution:
Apple has released an advisory along with fixes to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.5.1
Apple Mac OS X 10.5.1
Solution:
Apple has released an advisory along with fixes to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.4.11
-
Apple Security Update 2007-009 (10.4.11 PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg -
Apple Security Update 2007-009 (10.4.11 Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg
Apple Mac OS X 10.4.11
-
Apple Security Update 2007-009 (10.4.11 PPC)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg -
Apple Security Update 2007-009 (10.4.11 Universal)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16521&cat= 1&platform=osx&method=sa/SecUpd2007-009Univ.dmg
Apple Mac OS X Server 10.5.1
-
Apple Security Update 2007-009 (10.5.1)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16527&cat= 1&platform=osx&method=sa/SecUpd2007-009.dmg
Apple Mac OS X 10.5.1
-
Apple Security Update 2007-009 (10.5.1)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16527&cat= 1&platform=osx&method=sa/SecUpd2007-009.dmg
References
Apple Safari Subframe Same Origin Policy Violation Vulnerability
References:
References: