Back

MEDIUM

qt: Unallowed sub-resources loading in the media element handling code

Published Nov 13, 2009

Description

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 13, 2009
Updated Aug 7, 2024
Reserved Aug 17, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Nov 11, 2009