WebKit International CVE-2012-3693 Domain Name URI Spoofing Vulnerability
BID:54693
Info
WebKit International CVE-2012-3693 Domain Name URI Spoofing Vulnerability
| Bugtraq ID: | 54693 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3693 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2012 12:00AM |
| Updated: | Sep 19 2012 10:10PM |
| Credit: | Matt Cooley of Symantec |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit 2 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 5.0.6 Apple Safari 5.1.7 for Windows Apple Safari 5.1.7 Apple Safari 5.1.5 for Windows Apple Safari 5.1.4 for Windows Apple Safari 5.1.4 Apple Safari 5.1.1 for Windows Apple Safari 5.1.1 Apple Safari 5.1 for Windows Apple Safari 5.1 Apple Safari 5.0.6 for windows Apple Safari 5.0.5 for Windows Apple Safari 5.0.5 Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 |
| Not Vulnerable: | |
Discussion
WebKit International CVE-2012-3693 Domain Name URI Spoofing Vulnerability
WebKit is affected by a URI-spoofing vulnerability.
An attacker may leverage this issue to spoof the source URI of a site presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Note: This issue was previously discussed in BID 54669 (Apple Safari Prior to 6.0 Multiple Security Vulnerabilities), but has been given its own record to better document it.
WebKit is affected by a URI-spoofing vulnerability.
An attacker may leverage this issue to spoof the source URI of a site presented to an unsuspecting user. This may lead to a false sense of trust because the user may be presented with a source URI of a trusted site while interacting with the attacker's malicious site.
Note: This issue was previously discussed in BID 54669 (Apple Safari Prior to 6.0 Multiple Security Vulnerabilities), but has been given its own record to better document it.
Exploit / POC
WebKit International CVE-2012-3693 Domain Name URI Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
Solution / Fix
WebKit International CVE-2012-3693 Domain Name URI Spoofing Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
WebKit International CVE-2012-3693 Domain Name URI Spoofing Vulnerability
References:
References:
- Safari Homepage (Apple)
- Webkit Homepage (Webkit)