First published: Mon Nov 17 2008(Updated: )
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Safari | =1.3.2 | |
Safari | =2 | |
Safari | =1.1.1 | |
Safari | =3.0.4 | |
Safari | =1.2.2 | |
Safari | =2.0.1 | |
Safari | =3.0.1 | |
Safari | =2.0.3 | |
Safari | =1.0.3 | |
Safari | =2.0.2 | |
Safari | =3.0.1 | |
Safari | =3.0.2 | |
Safari | =1.0 | |
Safari | =2.0.4_419.3 | |
Safari | =3.1.1 | |
Safari | =1.3 | |
Safari | =3.0.3 | |
Safari | =3.0.2 | |
Safari | =3.1 | |
Safari | =1.2.5 | |
Safari | =3.0.3 | |
Safari | =3.0 | |
Safari | =2.0 | |
Safari | =1.2.4 | |
Safari | =1.2.1 | |
Safari | =1.0-beta | |
Safari | =0.8 | |
Safari | =2.0.4 | |
Safari | =1.0-beta2 | |
Safari | =1.1 | |
Safari | =1.3.1 | |
Safari | =1.2 | |
Safari | ||
Safari | <=3.1.2 | |
Safari | =2.0_pre | |
Safari | =3.0 | |
Safari | =3.0.4_beta | |
Safari | =2.0.3_417.9.3 | |
Safari | =1.2.3 | |
Safari | =3.0.4_beta | |
Safari | =3 | |
Safari | =0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4216 is classified as a moderate severity vulnerability.
To fix CVE-2008-4216, update to the latest version of Apple Safari that includes the security patches.
CVE-2008-4216 affects Apple Safari versions prior to 3.2.
CVE-2008-4216 is a vulnerability in the plug-in interface of WebKit in Apple Safari.
CVE-2008-4216 allows remote attackers to access sensitive information from local files on a user's system.