CVE Vulnerabilities

CVE-2009-2841

Published: Nov 13, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 4.0.3 (including)
Safari Apple 0.8 (including) 0.8 (including)
Safari Apple 0.9 (including) 0.9 (including)
Safari Apple 1.0 (including) 1.0 (including)
Safari Apple 1.0-beta (including) 1.0-beta (including)
Safari Apple 1.0-beta2 (including) 1.0-beta2 (including)
Safari Apple 1.0.0 (including) 1.0.0 (including)
Safari Apple 1.0.0b1 (including) 1.0.0b1 (including)
Safari Apple 1.0.0b2 (including) 1.0.0b2 (including)
Safari Apple 1.0.1 (including) 1.0.1 (including)
Safari Apple 1.0.2 (including) 1.0.2 (including)
Safari Apple 1.0.3 (including) 1.0.3 (including)
Safari Apple 1.1.0 (including) 1.1.0 (including)
Safari Apple 1.1.1 (including) 1.1.1 (including)
Safari Apple 1.2 (including) 1.2 (including)
Safari Apple 1.2.0 (including) 1.2.0 (including)
Safari Apple 1.2.1 (including) 1.2.1 (including)
Safari Apple 1.2.2 (including) 1.2.2 (including)
Safari Apple 1.2.3 (including) 1.2.3 (including)
Safari Apple 1.2.4 (including) 1.2.4 (including)
Safari Apple 1.2.5 (including) 1.2.5 (including)
Safari Apple 1.3 (including) 1.3 (including)
Safari Apple 1.3.0 (including) 1.3.0 (including)
Safari Apple 1.3.1 (including) 1.3.1 (including)
Safari Apple 1.3.2 (including) 1.3.2 (including)
Safari Apple 2 (including) 2 (including)
Safari Apple 2.0 (including) 2.0 (including)
Safari Apple 2.0.0 (including) 2.0.0 (including)
Safari Apple 2.0.1 (including) 2.0.1 (including)
Safari Apple 2.0.2 (including) 2.0.2 (including)
Safari Apple 2.0.3 (including) 2.0.3 (including)
Safari Apple 2.0.3-417.8 (including) 2.0.3-417.8 (including)
Safari Apple 2.0.3-417.9 (including) 2.0.3-417.9 (including)
Safari Apple 2.0.3-417.9.2 (including) 2.0.3-417.9.2 (including)
Safari Apple 2.0.3-417.9.3 (including) 2.0.3-417.9.3 (including)
Safari Apple 2.0.3_417.9.3 (including) 2.0.3_417.9.3 (including)
Safari Apple 2.0.4 (including) 2.0.4 (including)
Safari Apple 2.0.4_419.3 (including) 2.0.4_419.3 (including)
Safari Apple 2.0_pre (including) 2.0_pre (including)
Safari Apple 3 (including) 3 (including)
Safari Apple 3.0 (including) 3.0 (including)
Safari Apple 3.0.0 (including) 3.0.0 (including)
Safari Apple 3.0.0b (including) 3.0.0b (including)
Safari Apple 3.0.1 (including) 3.0.1 (including)
Safari Apple 3.0.1-beta (including) 3.0.1-beta (including)
Safari Apple 3.0.1b (including) 3.0.1b (including)
Safari Apple 3.0.2 (including) 3.0.2 (including)
Safari Apple 3.0.2b (including) 3.0.2b (including)
Safari Apple 3.0.3 (including) 3.0.3 (including)
Safari Apple 3.0.3b (including) 3.0.3b (including)
Safari Apple 3.0.4 (including) 3.0.4 (including)
Safari Apple 3.0.4_beta (including) 3.0.4_beta (including)
Safari Apple 3.0.4b (including) 3.0.4b (including)
Safari Apple 3.1 (including) 3.1 (including)
Safari Apple 3.1.0 (including) 3.1.0 (including)
Safari Apple 3.1.0b (including) 3.1.0b (including)
Safari Apple 3.1.1 (including) 3.1.1 (including)
Safari Apple 3.1.2 (including) 3.1.2 (including)
Safari Apple 3.2 (including) 3.2 (including)
Safari Apple 3.2.0 (including) 3.2.0 (including)
Safari Apple 3.2.1 (including) 3.2.1 (including)
Safari Apple 3.2.2 (including) 3.2.2 (including)
Safari Apple 3.2.3 (including) 3.2.3 (including)
Safari Apple 4.0 (including) 4.0 (including)
Safari Apple 4.0-beta (including) 4.0-beta (including)
Safari Apple 4.0.0b (including) 4.0.0b (including)
Safari Apple 4.0.1 (including) 4.0.1 (including)
Safari Apple 4.0.2 (including) 4.0.2 (including)

References