Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not indicate what web site originated an input prompt, which allows remote attackers to conduct spoofing attacks via a crafted site.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1033274 | vdb entry third party advisory |
https://support.apple.com/kb/HT205030 | vendor advisory |
http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/76342 | vdb entry third party advisory |
http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html | mailing list vendor advisory |
https://support.apple.com/kb/HT205033 | vendor advisory |