CVE-2008-1999: Medium severity safari vulnerability
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1999?
CVE-2008-1999 is considered a moderate severity vulnerability due to its potential to allow address bar spoofing.
How do I fix CVE-2008-1999?
To mitigate CVE-2008-1999, users should upgrade to a newer version of Apple Safari that has patched this vulnerability.
Which versions of Apple Safari are affected by CVE-2008-1999?
CVE-2008-1999 specifically affects Apple Safari version 3.1.1.
What type of attack does CVE-2008-1999 exploit?
CVE-2008-1999 exploits URL manipulation to spoof the address bar, leading users to believe they are visiting a legitimate site.
Is CVE-2008-1999 a widely exploited vulnerability?
As of the latest reports, CVE-2008-1999 has not been widely exploited in the wild, but it poses a risk due to its nature.