CVE-2009-1708: Critical severity Safari vulnerability
Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain sensitive information, via a crafted call.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1708?
CVE-2009-1708 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2009-1708?
To fix CVE-2009-1708, update Apple Safari to version 4.0 or later as the affected versions do not mitigate this vulnerability.
What versions of Apple Safari are affected by CVE-2009-1708?
CVE-2009-1708 affects Apple Safari versions before 4.0, including 3.1.2 through 3.2.3.
What type of vulnerability is CVE-2009-1708?
CVE-2009-1708 is a remote code execution vulnerability that could allow attackers to open local help files.
Can CVE-2009-1708 lead to data exposure?
Yes, CVE-2009-1708 can potentially expose sensitive information through arbitrary code execution on the user's system.