|
[Japanese]
|
JVNDB-2007-000727
|
Safari allows access from HTTP to HTTPS
|
Apple Safari contains a vulnerability that allows a remote attacker to access HTTPS content via an HTTP session.
Safari is a default web browser installed in Mac OS X and iPhone.
Safari contains a vulnerability that allows a remote attacker to access web page contents protected by SSL/TLS from an HTTP page in the same domain.
|
Base Metrics:
4.0 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Apple Inc.
- Safari 3.0.3 and earlier for Mac OS X, Windows XP / Vista
- Apple Mac OS X v10.4 - v10.4.10
- iPhone v1.1.1 before
|
|
A remote attacker could obtain or change the web page contents protected by SSL/TLS from an HTTP page in the same domain.
|
[Update the Software]
Apply the latest updates provided by the vendor.
For more information, refer to the vendor's website.
|
Apple Inc.
|
- Improper Input Validation(CWE-20) [NVD Evaluation]
|
- CVE-2007-4671
|
- JVN : JVN#79013771
- National Vulnerability Database (NVD) : CVE-2007-4671
- Secunia Advisory : SA26983
- SecurityFocus : 25852
- ISS X-Force Database : 36862
- SecurityTracker : 1018752
- FrSIRT Advisories : FrSIRT/ADV-2007-3287
|
[2008/05/21]
Web page published
|