CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/2316 | vdb entry |
http://docs.info.apple.com/article.html?artnum=306173 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35017 | vdb entry |
http://lists.apple.com/archives/Security-announce/2007/Jun/msg00003.html | patch vendor advisory |
http://secunia.com/advisories/25786 | third party advisory patch vendor advisory |
http://www.westpoint.ltd.uk/advisories/wp-07-0002.txt | patch vendor advisory |
http://secunia.com/advisories/26287 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/472198/100/0/threaded | mailing list |
http://docs.info.apple.com/article.html?artnum=305759 | |
http://www.securityfocus.com/bid/24598 | vdb entry patch |
http://www.vupen.com/english/advisories/2007/2731 | vdb entry |
http://osvdb.org/36449 | vdb entry |
http://www.securitytracker.com/id?1018281 | vdb entry patch |
http://www.vupen.com/english/advisories/2007/2296 | vdb entry |
http://www.kb.cert.org/vuls/id/845708 | third party advisory us government resource |