CERTA-2003-AVI-207
Vulnerability from certfr_avis

Une vulnérabilité sur le navigateur Apple Safari permet à un utilisateur mal intentionné de récupérer un cookie présent dans le cache du navigateur.

Description

Une vulnérabilité sur le navigateur Apple Safari permet à un utilisateur mal intentionné, via une page au format html malicieusement construite envoyée par mail ou hébergée sur un site web, de récupérer le contenu d'un cookie présent dans le cache de votre navigateur.

Solution

Appliquer les correctifs disponibles sur le site d'Apple (cf section documention).

None
Impacted products
Vendor Product Description
Apple Safari MacOS X 10.2.8 ;
Apple Safari MacOS X 10.3.1.
References

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "MacOS X 10.2.8 ;",
      "product": {
        "name": "Safari",
        "vendor": {
          "name": "Apple",
          "scada": false
        }
      }
    },
    {
      "description": "MacOS X 10.3.1.",
      "product": {
        "name": "Safari",
        "vendor": {
          "name": "Apple",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": null,
  "content": "## Description\n\nUne vuln\u00e9rabilit\u00e9 sur le navigateur Apple Safari permet \u00e0 un utilisateur\nmal intentionn\u00e9, via une page au format html malicieusement construite\nenvoy\u00e9e par mail ou h\u00e9berg\u00e9e sur un site web, de r\u00e9cup\u00e9rer le contenu\nd\u0027un cookie pr\u00e9sent dans le cache de votre navigateur.\n\n## Solution\n\nAppliquer les correctifs disponibles sur le site d\u0027Apple (cf section\ndocumention).\n",
  "cves": [],
  "initial_release_date": "2003-12-12T00:00:00",
  "last_revision_date": "2003-12-12T00:00:00",
  "links": [
    {
      "title": "Avis de s\u00e9curit\u00e9 Apple",
      "url": "http://docs.info.apple.com/article.html?artnum=61798"
    }
  ],
  "reference": "CERTA-2003-AVI-207",
  "revisions": [
    {
      "description": "version initiale.",
      "revision_date": "2003-12-12T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "Vol de cookies"
    }
  ],
  "summary": "Une vuln\u00e9rabilit\u00e9 sur le navigateur Apple Safari permet \u00e0 un utilisateur\nmal intentionn\u00e9 de r\u00e9cup\u00e9rer un cookie pr\u00e9sent dans le cache du\nnavigateur.\n",
  "title": "Vuln\u00e9rabilit\u00e9 sur le navigateur Apple Safari",
  "vendor_advisories": [
    {
      "published_at": null,
      "title": "Avis de s\u00e9curit\u00e9 SA10252 de S\u00e9cunia",
      "url": "http://www.secunia.com/advisories/10252/"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…