WebKit User Interface Cross Domain Spoofing Vulnerability
BID:41068
Info
WebKit User Interface Cross Domain Spoofing Vulnerability
| Bugtraq ID: | 41068 |
| Class: | Design Error |
| CVE: |
CVE-2010-1757 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2010 12:00AM |
| Updated: | Nov 22 2010 07:16PM |
| Credit: | Wayne Pan |
| Vulnerable: |
Apple iPod Touch 3.1.3 Apple iPod Touch 3.1.2 Apple iPod Touch 3.1.1 Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPod Touch 0 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 3.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 Apple iPhone 0 Apple iPad 3.2.1 Apple iPad 3.2.2 Apple iPad 3.2 Apple iPad 0 Apple iPad 0 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.2 beta Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 |
| Not Vulnerable: |
Apple iOS 4.2 Apple iOS 4 |
Discussion
WebKit User Interface Cross Domain Spoofing Vulnerability
WebKit is prone to a cross-domain spoofing vulnerability.
An attacker can exploit this vulnerability to bypass the same-origin policy and obtain potentially sensitive information, or to launch other attacks against sites.
NOTE: This issue was previously covered in BID 41016 (Apple iPhone/iPod touch Prior to iOS 4 Multiple Vulnerabilities) but has been given its own record to better document it.
WebKit is prone to a cross-domain spoofing vulnerability.
An attacker can exploit this vulnerability to bypass the same-origin policy and obtain potentially sensitive information, or to launch other attacks against sites.
NOTE: This issue was previously covered in BID 41016 (Apple iPhone/iPod touch Prior to iOS 4 Multiple Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
WebKit User Interface Cross Domain Spoofing Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Solution / Fix
WebKit User Interface Cross Domain Spoofing Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
WebKit User Interface Cross Domain Spoofing Vulnerability
References:
References:
- iOS 4 Software Update (Apple)
- iPhone Product Page (Apple)
- iPod touch Product Page (Apple)