First published: Wed Jun 10 2009(Updated: )
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | =3.1.2 | |
Apple Safari | =3.2.1 | |
Apple Safari | =0.9 | |
Apple Safari | =1.3.2 | |
Apple Safari | =1.2 | |
Apple Safari | =3.0.4 | |
Apple Safari | =3.0.3 | |
Apple Safari | =1.3.1 | |
Apple Safari | =2.0.4 | |
Apple Safari | =3.0 | |
Apple Safari | =3.2.3 | |
Apple Safari | =1.1 | |
Apple Safari | <=4.0_beta | |
Apple Safari | =3.1 | |
Apple Safari | =2.0 | |
Apple Safari | =3.0.2 | |
Apple Safari | =1.0.3 | |
Apple Safari | =1.0 | |
Apple Safari | =2.0.2 | |
Apple Safari | =3.1.1 | |
Apple Safari | =1.3 | |
Apple Safari | =0.8 | |
Apple Safari | =3.2 | |
Apple Safari | =3.0.3 | |
Apple Safari | =3.0.1 | |
Apple Safari | =3.1.2 | |
Apple Safari | <=3.2.3 | |
Apple Safari | =3.0.2 | |
Apple Safari | =3.1 | |
Apple Safari | =3.1.1 | |
Apple Safari | =3.0 | |
Apple Safari | =3.2.2 | |
Apple Safari | =3.2.1 | |
Apple Safari | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1716 has been classified as a moderate severity vulnerability.
To fix CVE-2009-1716, update your Apple Safari browser to version 4.0 or later.
CVE-2009-1716 allows local users to obtain sensitive information from unprotected temporary files.
CVE-2009-1716 affects Apple Safari versions prior to 4.0 on Windows and various earlier versions on macOS.
Yes, local users can exploit CVE-2009-1716 to read temporary download files and access potentially sensitive information.