LOW
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files
Published Jun 10, 2009
2.1
LOWCVSS 2.0
EPSS 0.42%
Description
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.
Affected products
No data.
Configuration 1
OR
- ≤ 4.0_beta
- 0.8
- 0.9
- 1.0
- 1.0.3
- 1.1
- 1.2
- 1.3
- 1.3.1
- 1.3.2
- 2.0
- 2.0.2
- 2.0.4
- 3.0
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.1
- 3.1.2
- 3.2.1
- 3.2.3
Configuration 2
OR
- ≤ 3.2.3
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.1
- 3.1.2
- 3.2
- 3.2.1
- 3.2.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://secunia.com/advisories/35379 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1022342 vdb-entryx_refsource_SECTRACK
- http://support.apple.com/kb/HT3613 x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/35260 vdb-entryx_refsource_BIDExploitPatch
- http://www.securityfocus.com/bid/35347 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/1522 vdb-entryx_refsource_VUPENPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html | vendor-advisoryx_refsource_APPLEPatchVendor Advisory | |
| http://secunia.com/advisories/35379 | third-party-advisoryx_refsource_SECUNIA | |
| http://securitytracker.com/id?1022342 | vdb-entryx_refsource_SECTRACK | |
| http://support.apple.com/kb/HT3613 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.securityfocus.com/bid/35260 | vdb-entryx_refsource_BIDExploitPatch | |
| http://www.securityfocus.com/bid/35347 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2009/1522 | vdb-entryx_refsource_VUPENPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 10, 2009
Updated Aug 7, 2024
Reserved May 20, 2009
Link CVE-2009-1716
CISA Vulnrichment
Updated n/a