Apple Safari Web Browser Null Character Cookie Stealing Vulnerability
BID:9065
Info
Apple Safari Web Browser Null Character Cookie Stealing Vulnerability
| Bugtraq ID: | 9065 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0975 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 18 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | This vulnerability was discovered by Austin Gilbert <[email protected]>. |
| Vulnerable: |
Apple Safari 1.1 Apple Safari 1.0 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.1 Apple Mac OS X 10.2.8 |
| Not Vulnerable: | |
Discussion
Apple Safari Web Browser Null Character Cookie Stealing Vulnerability
An issue has been discovered in Apple Safari, which may allow an attacker to steal cookie-based authentication credentials from a user of a vulnerable web browser. The problem is in the handling of NULL (%00) characters in URLs.
This issue may only be exploited to steal cookies set for a domain, as opposed to cookies set for a specific host in that domain. Cookies set with the secure flag can be stolen if the attacker uses SSL.
An issue has been discovered in Apple Safari, which may allow an attacker to steal cookie-based authentication credentials from a user of a vulnerable web browser. The problem is in the handling of NULL (%00) characters in URLs.
This issue may only be exploited to steal cookies set for a domain, as opposed to cookies set for a specific host in that domain. Cookies set with the secure flag can be stolen if the attacker uses SSL.
Exploit / POC
Apple Safari Web Browser Null Character Cookie Stealing Vulnerability
A demonstration of exploit was made available when the issues described in BID 3925 were initially released. This demo is said to still work on affected Apple Safari releases and can be found by referencing the following link:
http://alive.znep.com/~marcs/security/mozillacookie/cookies-redirect.cgi
A demonstration of exploit was made available when the issues described in BID 3925 were initially released. This demo is said to still work on affected Apple Safari releases and can be found by referencing the following link:
http://alive.znep.com/~marcs/security/mozillacookie/cookies-redirect.cgi
Solution / Fix
Apple Safari Web Browser Null Character Cookie Stealing Vulnerability
Solution:
Apple has released an advisory (APPLE-SA-2003-12-05) and fixes to address this issue. Please see referenced advisory for further details. Fixes are linked below.
Apple has released a Security Update to address this vulnerability:
Apple Safari 1.0
Apple Safari 1.1
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.1
Apple Mac OS X Server 10.3.1
Solution:
Apple has released an advisory (APPLE-SA-2003-12-05) and fixes to address this issue. Please see referenced advisory for further details. Fixes are linked below.
Apple has released a Security Update to address this vulnerability:
Apple Safari 1.0
-
Apple SecurityUpd2003-12-05Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-0935.20031205.cft4r/2Z/Sec urityUpd2003-12-05Jag.dmg
Apple Safari 1.1
-
Apple SecurityUpd2003-12-05Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-0935.20031205.cft4r/2Z/Sec urityUpd2003-12-05Jag.dmg
Apple Mac OS X 10.2.8
-
Apple SecurityUpd2003-12-05Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-0935.20031205.cft4r/2Z/Sec urityUpd2003-12-05Jag.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecurityUpd2003-12-05Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-0935.20031205.cft4r/2Z/Sec urityUpd2003-12-05Jag.dmg
Apple Mac OS X 10.3.1
-
Apple SecurityUpd2003-12-05.dmg
http://download.info.apple.com/Mac_OS_X/061-0970.20031205.Z2w34/2Z/Sec urityUpd2003-12-05.dmg
Apple Mac OS X Server 10.3.1
-
Apple SecurityUpd2003-12-05.dmg
http://download.info.apple.com/Mac_OS_X/061-0970.20031205.Z2w34/2Z/Sec urityUpd2003-12-05.dmg
References
Apple Safari Web Browser Null Character Cookie Stealing Vulnerability
References:
References:
- Security Update 2003-12-05 (Jaguar): Information and Download (Apple)
- Apple Safari 1.1 (v100) (Austin Gilbert
) - Re: Apple Safari 1.1 (v100) (Christian Horchert
) - Re: Apple Safari 1.1 (v100) (vm_converter
)