CVE-2009-2072: Medium severity Safari vulnerability
Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2072?
CVE-2009-2072 is considered to have a moderate severity, allowing man-in-the-middle attacks.
How do I fix CVE-2009-2072?
To fix CVE-2009-2072, update your Apple Safari browser to the latest version, which has patched this vulnerability.
Which versions of Apple Safari are affected by CVE-2009-2072?
CVE-2009-2072 affects multiple versions of Apple Safari, including versions from 0.8 to 3.2.1.
What type of attack is possible with CVE-2009-2072?
CVE-2009-2072 allows attackers to spoof HTTPS sites through man-in-the-middle attacks using crafted CONNECT response pages.
Is there a workaround for CVE-2009-2072 if I cannot update Apple Safari?
A temporary workaround for CVE-2009-2072 includes avoiding the use of proxy servers for secure connections until a fix can be applied.