WebKit Private Browsing Security Bypass Vulnerability
BID:50180
Info
WebKit Private Browsing Security Bypass Vulnerability
| Bugtraq ID: | 50180 |
| Class: | Design Error |
| CVE: |
CVE-2011-3242 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2011 12:00AM |
| Updated: | Oct 12 2011 12:00AM |
| Credit: | John Adamczyk |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r82222 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 2 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 Apple Safari 5.0.6 Apple Safari 5.1 Apple Safari 5.0.5 Apple Safari 5.0.4 Apple Safari 5.0.3 Apple Safari 5.0.2 Apple Safari 5.0.1 Apple Safari 5.0 Apple Mac OS X Server 10.7.2 Apple Mac OS X Server 10.6.8 Apple Mac OS X 10.7.2 Apple Mac OS X 10.6.8 |
| Not Vulnerable: |
Apple Safari 5.1.1 |
Discussion
WebKit Private Browsing Security Bypass Vulnerability
WebKit is prone to a security-bypass vulnerability. This issue occurs when private browsing mode is enabled.
Attackers can exploit this issue to bypass security restrictions.
NOTE: This issue was previously discussed in BID 50089 (Apple Safari Prior to 5.1.1 Multiple Security Vulnerabilities) but has been given its own record to better document it.
WebKit is prone to a security-bypass vulnerability. This issue occurs when private browsing mode is enabled.
Attackers can exploit this issue to bypass security restrictions.
NOTE: This issue was previously discussed in BID 50089 (Apple Safari Prior to 5.1.1 Multiple Security Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
WebKit Private Browsing Security Bypass Vulnerability
Attackers can exploit this issue through man-in-the-middle attacks.
Attackers can exploit this issue through man-in-the-middle attacks.
Solution / Fix
WebKit Private Browsing Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
WebKit Private Browsing Security Bypass Vulnerability
References:
References:
- Safari Homepage (Apple)
- Webkit Homepage (WebKit)