The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html | vendor advisory |
http://www.securitytracker.com/id?1021227 | vdb entry |
http://secunia.com/advisories/32706 | third party advisory |
http://www.securityfocus.com/bid/32291 | vdb entry |
http://support.apple.com/kb/HT3298 | vendor advisory |