CVE-2009-2062: Medium severity Safari vulnerability
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2062?
CVE-2009-2062 is classified as a high-severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2009-2062?
To fix CVE-2009-2062, it's recommended to upgrade to Apple Safari version 3.2.2 or later.
Which versions of Apple Safari are affected by CVE-2009-2062?
CVE-2009-2062 affects several versions of Apple Safari prior to 3.2.2.
What type of attack can be executed due to CVE-2009-2062?
CVE-2009-2062 allows man-in-the-middle attackers to execute arbitrary web scripts in an https site's context.
How was CVE-2009-2062 disclosed?
CVE-2009-2062 was disclosed through security research and documented in various security databases.