CVE Vulnerabilities

CVE-2009-2062

Improper Authentication

Published: Jun 15, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https sites context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 3.2.1 (including)
Safari Apple 0.8 (including) 0.8 (including)
Safari Apple 0.9 (including) 0.9 (including)
Safari Apple 1.0 (including) 1.0 (including)
Safari Apple 1.0-beta (including) 1.0-beta (including)
Safari Apple 1.0-beta2 (including) 1.0-beta2 (including)
Safari Apple 1.0.0 (including) 1.0.0 (including)
Safari Apple 1.0.0b1 (including) 1.0.0b1 (including)
Safari Apple 1.0.0b2 (including) 1.0.0b2 (including)
Safari Apple 1.0.1 (including) 1.0.1 (including)
Safari Apple 1.0.2 (including) 1.0.2 (including)
Safari Apple 1.0.3 (including) 1.0.3 (including)
Safari Apple 1.0.3-85.8 (including) 1.0.3-85.8 (including)
Safari Apple 1.0.3-85.8.1 (including) 1.0.3-85.8.1 (including)
Safari Apple 1.1 (including) 1.1 (including)
Safari Apple 1.1.0 (including) 1.1.0 (including)
Safari Apple 1.1.1 (including) 1.1.1 (including)
Safari Apple 1.2 (including) 1.2 (including)
Safari Apple 1.2.0 (including) 1.2.0 (including)
Safari Apple 1.2.1 (including) 1.2.1 (including)
Safari Apple 1.2.2 (including) 1.2.2 (including)
Safari Apple 1.2.3 (including) 1.2.3 (including)
Safari Apple 1.2.4 (including) 1.2.4 (including)
Safari Apple 1.2.5 (including) 1.2.5 (including)
Safari Apple 1.3 (including) 1.3 (including)
Safari Apple 1.3.0 (including) 1.3.0 (including)
Safari Apple 1.3.1 (including) 1.3.1 (including)
Safari Apple 1.3.2 (including) 1.3.2 (including)
Safari Apple 1.3.2-312.5 (including) 1.3.2-312.5 (including)
Safari Apple 1.3.2-312.6 (including) 1.3.2-312.6 (including)
Safari Apple 2 (including) 2 (including)
Safari Apple 2.0 (including) 2.0 (including)
Safari Apple 2.0.0 (including) 2.0.0 (including)
Safari Apple 2.0.1 (including) 2.0.1 (including)
Safari Apple 2.0.2 (including) 2.0.2 (including)
Safari Apple 2.0.3 (including) 2.0.3 (including)
Safari Apple 2.0.3-417.8 (including) 2.0.3-417.8 (including)
Safari Apple 2.0.3-417.9 (including) 2.0.3-417.9 (including)
Safari Apple 2.0.3-417.9.2 (including) 2.0.3-417.9.2 (including)
Safari Apple 2.0.3-417.9.3 (including) 2.0.3-417.9.3 (including)
Safari Apple 2.0.3_417.9.3 (including) 2.0.3_417.9.3 (including)
Safari Apple 2.0.4 (including) 2.0.4 (including)
Safari Apple 2.0.4_419.3 (including) 2.0.4_419.3 (including)
Safari Apple 2.0_pre (including) 2.0_pre (including)
Safari Apple 3 (including) 3 (including)
Safari Apple 3.0 (including) 3.0 (including)
Safari Apple 3.0.0 (including) 3.0.0 (including)
Safari Apple 3.0.0b (including) 3.0.0b (including)
Safari Apple 3.0.1 (including) 3.0.1 (including)
Safari Apple 3.0.1-beta (including) 3.0.1-beta (including)
Safari Apple 3.0.1b (including) 3.0.1b (including)
Safari Apple 3.0.2 (including) 3.0.2 (including)
Safari Apple 3.0.2b (including) 3.0.2b (including)
Safari Apple 3.0.3 (including) 3.0.3 (including)
Safari Apple 3.0.3-522.15.5 (including) 3.0.3-522.15.5 (including)
Safari Apple 3.0.3b (including) 3.0.3b (including)
Safari Apple 3.0.4 (including) 3.0.4 (including)
Safari Apple 3.0.4_beta (including) 3.0.4_beta (including)
Safari Apple 3.0.4b (including) 3.0.4b (including)
Safari Apple 3.1 (including) 3.1 (including)
Safari Apple 3.1.0 (including) 3.1.0 (including)
Safari Apple 3.1.0b (including) 3.1.0b (including)
Safari Apple 3.1.1 (including) 3.1.1 (including)
Safari Apple 3.1.2 (including) 3.1.2 (including)
Safari Apple 3.2 (including) 3.2 (including)
Safari Apple 3.2.0 (including) 3.2.0 (including)

Potential Mitigations

References