CVE-2007-4692: Medium severity Apple Safari vulnerability
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4692?
CVE-2007-4692 has a moderate severity level as it allows for potential phishing attacks.
How do I fix CVE-2007-4692?
To mitigate CVE-2007-4692, users should upgrade to Safari version 3.0.4 or later.
Which versions of Safari are affected by CVE-2007-4692?
CVE-2007-4692 affects Safari versions prior to 3.0.4.
What type of attack does CVE-2007-4692 enable?
CVE-2007-4692 enables remote attackers to spoof HTTP authentication dialogs, potentially leading to phishing.
On which operating systems does CVE-2007-4692 primarily affect Safari?
CVE-2007-4692 primarily affects Safari on Windows and Mac OS X 10.4 through 10.4.10.