CVE-2009-2199: Medium severity safari vulnerability
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2199?
CVE-2009-2199 is considered a moderate security vulnerability that could allow for domain spoofing.
How do I fix CVE-2009-2199?
To fix CVE-2009-2199, upgrade to Apple Safari version 4.0.3 or later.
What platforms are affected by CVE-2009-2199?
CVE-2009-2199 affects Apple Safari versions prior to 4.0.3, alongside various iPhone OS versions.
Can CVE-2009-2199 lead to phishing attacks?
Yes, CVE-2009-2199 can potentially enable phishing attacks by allowing attackers to spoof domain names in URLs.
Who are the potential attackers in CVE-2009-2199?
Remote attackers can exploit CVE-2009-2199 to conduct attacks against vulnerable versions of Safari.