CVE-2009-2058: Medium severity Safari vulnerability
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2058?
CVE-2009-2058 has a high severity rating as it allows man-in-the-middle attackers to execute arbitrary web scripts.
How do I fix CVE-2009-2058?
To fix CVE-2009-2058, ensure that you update Apple Safari to version 3.2.2 or later.
What versions of Safari are affected by CVE-2009-2058?
CVE-2009-2058 affects all versions of Apple Safari prior to 3.2.2.
What type of attack does CVE-2009-2058 describe?
CVE-2009-2058 describes an "SSL tampering" attack that exploits HTTP Host headers in proxy responses.
Can CVE-2009-2058 compromise user data?
Yes, CVE-2009-2058 can potentially compromise user data by allowing attackers to execute arbitrary scripts in the user's browser.