CVE-2009-2841

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.
References
Link Resource
http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html Patch Vendor Advisory
http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://osvdb.org/59941
http://secunia.com/advisories/37346
http://secunia.com/advisories/40557
http://secunia.com/advisories/41856
http://secunia.com/advisories/43068
http://support.apple.com/kb/HT3949 Patch Vendor Advisory
http://support.apple.com/kb/HT4013
http://threatpost.com/en_us/blogs/apple-patches-critical-safari-vulnerabilities-111109
http://trac.webkit.org/changeset/49480
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://www.securityfocus.com/bid/36996
http://www.securitytracker.com/id?1023167
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2009/3217
http://www.vupen.com/english/advisories/2010/1801
http://www.vupen.com/english/advisories/2010/2722
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2011/0552
https://bugzilla.redhat.com/show_bug.cgi?id=525791
https://exchange.xforce.ibmcloud.com/vulnerabilities/54242
http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html Patch Vendor Advisory
http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://osvdb.org/59941
http://secunia.com/advisories/37346
http://secunia.com/advisories/40557
http://secunia.com/advisories/41856
http://secunia.com/advisories/43068
http://support.apple.com/kb/HT3949 Patch Vendor Advisory
http://support.apple.com/kb/HT4013
http://threatpost.com/en_us/blogs/apple-patches-critical-safari-vulnerabilities-111109
http://trac.webkit.org/changeset/49480
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://www.securityfocus.com/bid/36996
http://www.securitytracker.com/id?1023167
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2009/3217
http://www.vupen.com/english/advisories/2010/1801
http://www.vupen.com/english/advisories/2010/2722
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2011/0552
https://bugzilla.redhat.com/show_bug.cgi?id=525791
https://exchange.xforce.ibmcloud.com/vulnerabilities/54242
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0:beta:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.0b1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.0b2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.3:417.8:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.3:417.9:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.3:417.9.2:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.3:417.9.3:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.3_417.9.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.4_419.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0_pre:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.0b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.1:beta:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.1b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.2b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.3b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.4_beta:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.4b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.0b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0:beta:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:05

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html - Patch, Vendor Advisory () http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html - Patch, Vendor Advisory
References () http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html - () http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html -
References () http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html -
References () http://osvdb.org/59941 - () http://osvdb.org/59941 -
References () http://secunia.com/advisories/37346 - () http://secunia.com/advisories/37346 -
References () http://secunia.com/advisories/40557 - () http://secunia.com/advisories/40557 -
References () http://secunia.com/advisories/41856 - () http://secunia.com/advisories/41856 -
References () http://secunia.com/advisories/43068 - () http://secunia.com/advisories/43068 -
References () http://support.apple.com/kb/HT3949 - Patch, Vendor Advisory () http://support.apple.com/kb/HT3949 - Patch, Vendor Advisory
References () http://support.apple.com/kb/HT4013 - () http://support.apple.com/kb/HT4013 -
References () http://threatpost.com/en_us/blogs/apple-patches-critical-safari-vulnerabilities-111109 - () http://threatpost.com/en_us/blogs/apple-patches-critical-safari-vulnerabilities-111109 -
References () http://trac.webkit.org/changeset/49480 - () http://trac.webkit.org/changeset/49480 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 - () http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 -
References () http://www.securityfocus.com/bid/36996 - () http://www.securityfocus.com/bid/36996 -
References () http://www.securitytracker.com/id?1023167 - () http://www.securitytracker.com/id?1023167 -
References () http://www.ubuntu.com/usn/USN-1006-1 - () http://www.ubuntu.com/usn/USN-1006-1 -
References () http://www.vupen.com/english/advisories/2009/3217 - () http://www.vupen.com/english/advisories/2009/3217 -
References () http://www.vupen.com/english/advisories/2010/1801 - () http://www.vupen.com/english/advisories/2010/1801 -
References () http://www.vupen.com/english/advisories/2010/2722 - () http://www.vupen.com/english/advisories/2010/2722 -
References () http://www.vupen.com/english/advisories/2011/0212 - () http://www.vupen.com/english/advisories/2011/0212 -
References () http://www.vupen.com/english/advisories/2011/0552 - () http://www.vupen.com/english/advisories/2011/0552 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=525791 - () https://bugzilla.redhat.com/show_bug.cgi?id=525791 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54242 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54242 -

Information

Published : 2009-11-13 15:30

Updated : 2024-11-21 01:05


NVD link : CVE-2009-2841

Mitre link : CVE-2009-2841

CVE.ORG link : CVE-2009-2841


JSON object : View

Products Affected

apple

  • mac_os_x
  • safari