Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html | vendor advisory |
http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html | vendor advisory |
http://www.vupen.com/english/advisories/2008/3232 | vdb entry |
http://secunia.com/advisories/32706 | third party advisory |
http://www.securityfocus.com/bid/32291 | vdb entry |
http://support.apple.com/kb/HT3318 | |
http://www.securitytracker.com/id?1021226 | vdb entry |
http://support.apple.com/kb/HT3298 | vendor advisory |
http://secunia.com/advisories/32756 | third party advisory |