First published: Mon Jun 25 2007(Updated: )
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=1.0 | |
Apple Mac OS X | =10.3.9 | |
Apple Mac OS X | =10.4.9 | |
Apple Mac OS X Server | =10.3.9 | |
Apple Mac OS X Server | =10.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.