WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/41329 | vdb entry |
http://www.securitytracker.com/id?1019656 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-079A.html | third party advisory us government resource |
http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html | vendor advisory |
http://www.securityfocus.com/bid/28290 | vdb entry |
http://docs.info.apple.com/article.html?artnum=307563 | |
http://www.securityfocus.com/bid/28326 | vdb entry |
http://www.vupen.com/english/advisories/2008/0920/references | vdb entry |
http://secunia.com/advisories/29393 | third party advisory |