WebKit Private Browsing CVE-2014-4409 Security Bypass Vulnerability
BID:69937
Info
WebKit Private Browsing CVE-2014-4409 Security Bypass Vulnerability
| Bugtraq ID: | 69937 |
| Class: | Design Error |
| CVE: |
CVE-2014-4409 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2014 12:00AM |
| Updated: | Sep 17 2014 12:00AM |
| Credit: | Yosuke Hasegawa (NetAgent Co., Led.) |
| Vulnerable: |
Apple Safari 7.0.6 Apple Safari 7.0.3 Apple Safari 7.0.1 Apple Safari 6.1.6 Apple Safari 6.1.3 Apple Safari 6.1.1 Apple Safari 6.0.5 Apple Safari 6.0.4 Apple Safari 6.0.3 Apple Safari 6.0.2 Apple Safari 6.0.1 Apple Safari 5.1.10 Apple Safari 5.1.6 Apple Safari 5.1.5 Apple Safari 5.0.6 Apple Safari 4.0.5 Apple Safari 4.0.4 Apple Safari 4.0.3 Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 3.2.3 Apple Safari 3.1.2 Apple Safari 3.1.1 Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.2 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari 7.0.5 Apple Safari 7.0.4 Apple Safari 7.0.2 Apple Safari 6.1.5 Apple Safari 6.1.4 Apple Safari 6.1.2 Apple Safari 6.1 Apple Safari 6.0 Apple Safari 5.34 Apple Safari 5.33 Apple Safari 5.31 Apple Safari 5.1.7 Apple Safari 5.1.4 Apple Safari 5.1.3 Apple Safari 5.1.2 Apple Safari 5.1.1 Apple Safari 5.1 Apple Safari 5.0.5 Apple Safari 5.0.4 Apple Safari 5.0.3 Apple Safari 5.0.2 Apple Safari 5.0.1 Apple Safari 5.0 Apple Safari 4.31 Apple Safari 4.30 Apple Safari 4.28 Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Apple Safari 4 Apple Safari 3.52 Apple Safari 3.2 Apple Safari 3.1 Apple Safari 3 Apple Safari 0 Apple iOS 7.0.6 Apple iOS 7.0.3 Apple iOS 7.0.2 Apple iOS 7.0.1 Apple iOS 6.3.1 Apple iOS 6.1.6 Apple iOS 6.1.4 Apple iOS 6.1.3 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 7.1.2 Apple iOS 7.1.1 Apple iOS 7.1 Apple iOS 7.0.4 Apple iOS 7 Apple iOS 6.1 Apple iOS 6.0.2 Apple iOS 6.0.1 Apple iOS 6 for Developer Apple iOS 6 Beta 4 Apple iOS 6 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 |
| Not Vulnerable: |
Apple Safari 7.1 Apple Safari 6.2 Apple iOS 8 |
Exploit / POC
WebKit Private Browsing CVE-2014-4409 Security Bypass Vulnerability
Attackers can exploit this issue through man-in-the-middle attacks.
Attackers can exploit this issue through man-in-the-middle attacks.
Solution / Fix
WebKit Private Browsing CVE-2014-4409 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.