WebKit Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:52367
Info
WebKit Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 52367 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0586 CVE-2012-0587 CVE-2012-0588 CVE-2012-0589 CVE-2012-0590 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2012 12:00AM |
| Updated: | Mar 12 2012 07:50PM |
| Credit: | Sergey Glazunov, Jochen Eisinger of Google Chrome Team, Alan Austin of polyvore.com, and Adam Barth of Google Chrome Security Team |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 2 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 5.0.6 Apple Safari 4.1.2 for Windows Apple Safari 4.0.5 for Windows Apple Safari 4.0.5 Apple Safari 4.0.4 for Windows Apple Safari 4.0.4 Apple Safari 4.0.3 for Windows Apple Safari 4.0.3 Apple Safari 4.0.2 for Windows Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 3.2.3 for Windows Apple Safari 3.2.3 Apple Safari 5.1.1 for Windows Apple Safari 5.1.1 Apple Safari 5.1 for Windows Apple Safari 5.1 Apple Safari 5.0.6 for windows Apple Safari 5.0.5 for Windows Apple Safari 5.0.5 Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple Safari 4.1.3 for Windows Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Beta Apple Safari 4.0 Apple Safari 4 for Windows Apple Safari 4 Beta Apple Safari 4 Apple iPod Touch 0 Apple iPhone 4.0.1 Apple iPhone 3.2.1 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 4.3.3 Apple iPhone 4.3.2 Apple iPhone 4.3.1 Apple iPhone 4.3.0 Apple iPhone 4.2.8 Apple iPhone 4.2.5 Apple iPhone 4.2.1 Apple iPhone 4.1 Apple iPhone 4.0.2 Apple iPhone 4.0.1 - Ipodtouch Apple iPhone 4.0.1 - Iphone Apple iPhone 4.0 - Ipodtouch Apple iPhone 4.0 - Iphone Apple iPhone 4.0 Apple iPhone 3.2.2 Apple iPhone 3.2.1 - Ipad Apple iPhone 3.2 - Ipodtouch Apple iPhone 3.2 - Iphone Apple iPhone 3.2 Apple iPhone 3.1.3 - Ipodtouch Apple iPhone 3.1.3 - Iphone Apple iPhone 3.1.2 - Ipodtouch Apple iPhone 3.1.2 - Iphone Apple iPhone 3.1 - Ipodtouch Apple iPhone 3.1 - Iphone Apple iPhone 3.1 Apple iPhone 3.0.1 - Ipodtouch Apple iPhone 3.0.1 - Iphone Apple iPhone 3.0 - Ipodtouch Apple iPhone 3.0 - Iphone Apple iPhone 3.0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 |
| Not Vulnerable: |
Apple Safari 5.1.4 for Windows Apple Safari 5.1.4 Apple iOS 5.1 |
Discussion
WebKit Multiple Unspecified Cross Site Scripting Vulnerabilities
WebKit is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
WebKit is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
WebKit Multiple Unspecified Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
WebKit Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
WebKit Multiple Unspecified Cross Site Scripting Vulnerabilities
References:
References:
- Apple Homepage (Apple)
- WebKit Homepage (WebKit)