First published: Tue Aug 04 2009(Updated: )
Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple GarageBand | <=5.0.2 | |
Apple GarageBand | =4.1.1 | |
Apple GarageBand | =4.1.2 | |
Apple GarageBand | =5.0 | |
Apple GarageBand | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2198 is considered a moderate severity vulnerability due to its potential to enable user tracking.
To mitigate CVE-2009-2198, users should upgrade to Apple GarageBand version 5.1 or later.
CVE-2009-2198 affects Apple GarageBand versions 4.1.1 through 5.0.2.
CVE-2009-2198 allows remote web servers to track users more easily by accepting all cookies regardless of domain.
If you are using Apple GarageBand version 5.0.2 or earlier, your device is vulnerable to CVE-2009-2198.