CVE-2009-1699: Infoleak
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1699?
CVE-2009-1699 has been classified as a moderate severity vulnerability.
What software versions are affected by CVE-2009-1699?
CVE-2009-1699 affects Apple Safari versions prior to 4.0, as well as specific versions of iPhone OS and iPod touch firmware.
How do I fix CVE-2009-1699?
To fix CVE-2009-1699, update Apple Safari and iPhone OS to the latest versions that address this vulnerability.
What type of vulnerability is CVE-2009-1699?
CVE-2009-1699 is an XML external entity vulnerability that allows unauthorized file access.
Can CVE-2009-1699 be exploited remotely?
Yes, CVE-2009-1699 can be exploited remotely through crafted DTD files.