WebKit Local Webpage Cross Domain Information Disclosure Vulnerability
BID:46816
Info
WebKit Local Webpage Cross Domain Information Disclosure Vulnerability
| Bugtraq ID: | 46816 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2011-0167 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2011 12:00AM |
| Updated: | Mar 18 2011 08:27PM |
| Credit: | Aaron Sigel of vtty.com |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 |
| Not Vulnerable: |
Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 |
Discussion
WebKit Local Webpage Cross Domain Information Disclosure Vulnerability
WebKit is prone to a cross-domain scripting vulnerability because it fails to properly enforce the same-origin policy.
Successfully exploiting this issue will allow attackers to send the content of arbitrary files from the user's system to a remote server controlled by them. This results in disclosure of potentially sensitive information which may aid in further attacks.
WebKit is prone to a cross-domain scripting vulnerability because it fails to properly enforce the same-origin policy.
Successfully exploiting this issue will allow attackers to send the content of arbitrary files from the user's system to a remote server controlled by them. This results in disclosure of potentially sensitive information which may aid in further attacks.
Exploit / POC
WebKit Local Webpage Cross Domain Information Disclosure Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious website.
The following exploit code is available:
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious website.
The following exploit code is available:
Solution / Fix
WebKit Local Webpage Cross Domain Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
WebKit Local Webpage Cross Domain Information Disclosure Vulnerability
References:
References:
- Safari Errorjacking - CVE-2011-0167 (Aaron Sigel)
- Safari Homepage (Apple)
- Webkit Homepage (Webkit)