WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."
Link | Tags |
---|---|
http://support.apple.com/kb/HT3639 | |
http://secunia.com/advisories/43068 | third party advisory |
http://www.vupen.com/english/advisories/2009/1621 | vdb entry |
http://www.vupen.com/english/advisories/2011/0212 | vdb entry |
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html | vendor advisory |
http://www.securityfocus.com/bid/35260 | vdb entry |
http://osvdb.org/55005 | vdb entry |
http://www.vupen.com/english/advisories/2009/1522 | patch vendor advisory vdb entry |
http://secunia.com/advisories/37746 | third party advisory |
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html | vendor advisory |
http://www.debian.org/security/2009/dsa-1950 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html | vendor advisory |
http://secunia.com/advisories/35379 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/35322 | vdb entry |
http://support.apple.com/kb/HT3613 | vendor advisory |