CVE Vulnerabilities

CVE-2009-2841

Published: Nov 13, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*4.0.3 (including)
SafariApple0.8 (including)0.8 (including)
SafariApple0.9 (including)0.9 (including)
SafariApple1.0 (including)1.0 (including)
SafariApple1.0-beta (including)1.0-beta (including)
SafariApple1.0-beta2 (including)1.0-beta2 (including)
SafariApple1.0.0 (including)1.0.0 (including)
SafariApple1.0.0b1 (including)1.0.0b1 (including)
SafariApple1.0.0b2 (including)1.0.0b2 (including)
SafariApple1.0.1 (including)1.0.1 (including)
SafariApple1.0.2 (including)1.0.2 (including)
SafariApple1.0.3 (including)1.0.3 (including)
SafariApple1.1.0 (including)1.1.0 (including)
SafariApple1.1.1 (including)1.1.1 (including)
SafariApple1.2 (including)1.2 (including)
SafariApple1.2.0 (including)1.2.0 (including)
SafariApple1.2.1 (including)1.2.1 (including)
SafariApple1.2.2 (including)1.2.2 (including)
SafariApple1.2.3 (including)1.2.3 (including)
SafariApple1.2.4 (including)1.2.4 (including)
SafariApple1.2.5 (including)1.2.5 (including)
SafariApple1.3 (including)1.3 (including)
SafariApple1.3.0 (including)1.3.0 (including)
SafariApple1.3.1 (including)1.3.1 (including)
SafariApple1.3.2 (including)1.3.2 (including)
SafariApple2 (including)2 (including)
SafariApple2.0 (including)2.0 (including)
SafariApple2.0.0 (including)2.0.0 (including)
SafariApple2.0.1 (including)2.0.1 (including)
SafariApple2.0.2 (including)2.0.2 (including)
SafariApple2.0.3 (including)2.0.3 (including)
SafariApple2.0.3-417.8 (including)2.0.3-417.8 (including)
SafariApple2.0.3-417.9 (including)2.0.3-417.9 (including)
SafariApple2.0.3-417.9.2 (including)2.0.3-417.9.2 (including)
SafariApple2.0.3-417.9.3 (including)2.0.3-417.9.3 (including)
SafariApple2.0.3_417.9.3 (including)2.0.3_417.9.3 (including)
SafariApple2.0.4 (including)2.0.4 (including)
SafariApple2.0.4_419.3 (including)2.0.4_419.3 (including)
SafariApple2.0_pre (including)2.0_pre (including)
SafariApple3 (including)3 (including)
SafariApple3.0 (including)3.0 (including)
SafariApple3.0.0 (including)3.0.0 (including)
SafariApple3.0.0b (including)3.0.0b (including)
SafariApple3.0.1 (including)3.0.1 (including)
SafariApple3.0.1-beta (including)3.0.1-beta (including)
SafariApple3.0.1b (including)3.0.1b (including)
SafariApple3.0.2 (including)3.0.2 (including)
SafariApple3.0.2b (including)3.0.2b (including)
SafariApple3.0.3 (including)3.0.3 (including)
SafariApple3.0.3b (including)3.0.3b (including)
SafariApple3.0.4 (including)3.0.4 (including)
SafariApple3.0.4_beta (including)3.0.4_beta (including)
SafariApple3.0.4b (including)3.0.4b (including)
SafariApple3.1 (including)3.1 (including)
SafariApple3.1.0 (including)3.1.0 (including)
SafariApple3.1.0b (including)3.1.0b (including)
SafariApple3.1.1 (including)3.1.1 (including)
SafariApple3.1.2 (including)3.1.2 (including)
SafariApple3.2 (including)3.2 (including)
SafariApple3.2.0 (including)3.2.0 (including)
SafariApple3.2.1 (including)3.2.1 (including)
SafariApple3.2.2 (including)3.2.2 (including)
SafariApple3.2.3 (including)3.2.3 (including)
SafariApple4.0 (including)4.0 (including)
SafariApple4.0-beta (including)4.0-beta (including)
SafariApple4.0.0b (including)4.0.0b (including)
SafariApple4.0.1 (including)4.0.1 (including)
SafariApple4.0.2 (including)4.0.2 (including)
Qt4-x11Ubuntuintrepid*
Qt4-x11Ubuntujaunty*
Qt4-x11Ubuntukarmic*
WebkitUbuntuhardy*
WebkitUbuntuintrepid*
WebkitUbuntujaunty*
WebkitUbuntukarmic*

References