First published: Tue Oct 25 2005(Updated: )
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =2.0 | |
Apple macOS Server | =10.3.9 | |
Apple iOS and macOS | =10.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2524 is classified as a moderate severity vulnerability due to its ability to bypass domain restrictions.
To mitigate CVE-2005-2524, users should update their Safari browser and Mac OS X to the latest available versions.
CVE-2005-2524 exploits the ability of crafted web archives to misrepresent their source domain in Safari.
CVE-2005-2524 affects Apple Safari version 2.0 on Mac OS X 10.3.9 and Mac OS X Server 10.3.9.
Yes, CVE-2005-2524 can potentially lead to data leakage by allowing attackers to impersonate trusted sites.