MEDIUM
CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header
Published Jun 10, 2009
4.3
MEDIUMCVSS 2.0
EPSS 2.99%
Description
CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header.
Affected products
No data.
Configuration 1
OR
- ≤ 4.0_beta
- 0.8
- 0.9
- 1.0
- 1.0.3
- 1.1
- 1.2
- 1.3
- 1.3.1
- 1.3.2
- 2.0
- 2.0.2
- 2.0.4
- 3.0
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.1
- 3.1.2
- 3.2.1
- 3.2.3
Configuration 2
OR
- ≤ 3.2.3
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.1
- 3.1.2
- 3.2
- 3.2.1
- 3.2.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/54992 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/35379 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37746 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1022344 vdb-entryx_refsource_SECTRACKPatch
- http://support.apple.com/kb/HT3613 x_refsource_CONFIRMPatchVendor Advisory
- http://support.apple.com/kb/HT3639 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1950 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/35260 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2009/1522 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1621 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 10, 2009
Updated Aug 7, 2024
Reserved May 20, 2009
Link CVE-2009-1697
CISA Vulnrichment
Updated n/a