CVE Vulnerabilities

CVE-2009-2841

Published: Nov 13, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 4.0.3 (including)
Safari Apple 0.8 (including) 0.8 (including)
Safari Apple 0.9 (including) 0.9 (including)
Safari Apple 1.0 (including) 1.0 (including)
Safari Apple 1.0-beta (including) 1.0-beta (including)
Safari Apple 1.0-beta2 (including) 1.0-beta2 (including)
Safari Apple 1.0.0 (including) 1.0.0 (including)
Safari Apple 1.0.0b1 (including) 1.0.0b1 (including)
Safari Apple 1.0.0b2 (including) 1.0.0b2 (including)
Safari Apple 1.0.1 (including) 1.0.1 (including)
Safari Apple 1.0.2 (including) 1.0.2 (including)
Safari Apple 1.0.3 (including) 1.0.3 (including)
Safari Apple 1.1.0 (including) 1.1.0 (including)
Safari Apple 1.1.1 (including) 1.1.1 (including)
Safari Apple 1.2 (including) 1.2 (including)
Safari Apple 1.2.0 (including) 1.2.0 (including)
Safari Apple 1.2.1 (including) 1.2.1 (including)
Safari Apple 1.2.2 (including) 1.2.2 (including)
Safari Apple 1.2.3 (including) 1.2.3 (including)
Safari Apple 1.2.4 (including) 1.2.4 (including)
Safari Apple 1.2.5 (including) 1.2.5 (including)
Safari Apple 1.3 (including) 1.3 (including)
Safari Apple 1.3.0 (including) 1.3.0 (including)
Safari Apple 1.3.1 (including) 1.3.1 (including)
Safari Apple 1.3.2 (including) 1.3.2 (including)
Safari Apple 2 (including) 2 (including)
Safari Apple 2.0 (including) 2.0 (including)
Safari Apple 2.0.0 (including) 2.0.0 (including)
Safari Apple 2.0.1 (including) 2.0.1 (including)
Safari Apple 2.0.2 (including) 2.0.2 (including)
Safari Apple 2.0.3 (including) 2.0.3 (including)
Safari Apple 2.0.3-417.8 (including) 2.0.3-417.8 (including)
Safari Apple 2.0.3-417.9 (including) 2.0.3-417.9 (including)
Safari Apple 2.0.3-417.9.2 (including) 2.0.3-417.9.2 (including)
Safari Apple 2.0.3-417.9.3 (including) 2.0.3-417.9.3 (including)
Safari Apple 2.0.3_417.9.3 (including) 2.0.3_417.9.3 (including)
Safari Apple 2.0.4 (including) 2.0.4 (including)
Safari Apple 2.0.4_419.3 (including) 2.0.4_419.3 (including)
Safari Apple 2.0_pre (including) 2.0_pre (including)
Safari Apple 3 (including) 3 (including)
Safari Apple 3.0 (including) 3.0 (including)
Safari Apple 3.0.0 (including) 3.0.0 (including)
Safari Apple 3.0.0b (including) 3.0.0b (including)
Safari Apple 3.0.1 (including) 3.0.1 (including)
Safari Apple 3.0.1-beta (including) 3.0.1-beta (including)
Safari Apple 3.0.1b (including) 3.0.1b (including)
Safari Apple 3.0.2 (including) 3.0.2 (including)
Safari Apple 3.0.2b (including) 3.0.2b (including)
Safari Apple 3.0.3 (including) 3.0.3 (including)
Safari Apple 3.0.3b (including) 3.0.3b (including)
Safari Apple 3.0.4 (including) 3.0.4 (including)
Safari Apple 3.0.4_beta (including) 3.0.4_beta (including)
Safari Apple 3.0.4b (including) 3.0.4b (including)
Safari Apple 3.1 (including) 3.1 (including)
Safari Apple 3.1.0 (including) 3.1.0 (including)
Safari Apple 3.1.0b (including) 3.1.0b (including)
Safari Apple 3.1.1 (including) 3.1.1 (including)
Safari Apple 3.1.2 (including) 3.1.2 (including)
Safari Apple 3.2 (including) 3.2 (including)
Safari Apple 3.2.0 (including) 3.2.0 (including)
Safari Apple 3.2.1 (including) 3.2.1 (including)
Safari Apple 3.2.2 (including) 3.2.2 (including)
Safari Apple 3.2.3 (including) 3.2.3 (including)
Safari Apple 4.0 (including) 4.0 (including)
Safari Apple 4.0-beta (including) 4.0-beta (including)
Safari Apple 4.0.0b (including) 4.0.0b (including)
Safari Apple 4.0.1 (including) 4.0.1 (including)
Safari Apple 4.0.2 (including) 4.0.2 (including)
Qt4-x11 Ubuntu intrepid *
Qt4-x11 Ubuntu jaunty *
Qt4-x11 Ubuntu karmic *
Webkit Ubuntu hardy *
Webkit Ubuntu intrepid *
Webkit Ubuntu jaunty *
Webkit Ubuntu karmic *

References