Summary
This host has Apple Safari installed and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to bypass certain security restrictions, disclose sensitive information, or compromise a user's system.
Impact Level: Application
Solution
Upgrade to Safari version 4.0.4 or latest version.
http://www.apple.com/safari/download/
Insight
- An error exists in WebKit when sending 'preflight' requests originating from a page in a different origin. This can be exploited to facilitate cross-site request forgery attacks by injecting custom HTTP headers.
- An error exists when handling an 'Open Image in New Tab', 'Open Image in' 'New Window', or 'Open Link in New Tab' shortcut menu action performed on a link to a local file. This can be exploited to load a local HTML file and disclose sensitive information by tricking a user into performing the affected actions within a specially crafted webpage.
- Multiple errors in WebKit when handling FTP directory listings can be exploited to disclose sensitive information.
Affected
Apple Safari version prior to 4.0.4
References
Severity
Classification
-
CVE CVE-2009-2816, CVE-2009-2842, CVE-2009-3384 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities