CVE-2009-1713: Infoleak
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1713?
CVE-2009-1713 is considered a critical vulnerability due to its potential to allow remote attackers to read arbitrary local files.
How do I fix CVE-2009-1713?
To fix CVE-2009-1713, upgrade your Apple Safari browser to version 4.0 or later.
What versions of Safari are affected by CVE-2009-1713?
CVE-2009-1713 affects multiple versions of Safari prior to 4.0, including versions 1.1 to 3.2.3.
What is the impact of CVE-2009-1713?
The impact of CVE-2009-1713 includes unauthorized access to local files and cross-zone file access, compromising user privacy.
What type of attack does CVE-2009-1713 allow?
CVE-2009-1713 allows remote attackers to exploit the vulnerability via crafted XSLT files to read local and other zone files.