CVE-2009-2200: Infoleak
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2200?
CVE-2009-2200 is classified as a vulnerability impacting the Apple Safari web browser due to improper restrictions on URL schemes.
How do I fix CVE-2009-2200?
To fix CVE-2009-2200, update to Apple Safari version 4.0.3 or later, which addresses this vulnerability.
Which versions of Safari are affected by CVE-2009-2200?
CVE-2009-2200 affects Apple Safari versions earlier than 4.0.3.
Can CVE-2009-2200 lead to data theft?
Yes, CVE-2009-2200 can potentially allow attackers to access sensitive information through malicious HTML documents.
Is there a workaround for CVE-2009-2200?
No specific workaround exists for CVE-2009-2200; the recommended action is to update the browser to a secure version.