WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://support.apple.com/kb/HT4808 | |
http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html | patch vendor advisory |