CVE-2010-1388: Infoleak
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a crafted HTML document.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1388?
CVE-2010-1388 has a medium severity rating, primarily due to the potential for user-assisted exploitation.
How do I fix CVE-2010-1388?
To mitigate CVE-2010-1388, update to Apple Safari version 5.0 or later.
What are the affected software versions for CVE-2010-1388?
CVE-2010-1388 affects Apple Safari versions prior to 5.0 on Mac OS X 10.5 and 10.6, and prior to 4.1 on Mac OS X 10.4.
How does CVE-2010-1388 exploit the clipboard?
CVE-2010-1388 allows attackers to read arbitrary files through crafted HTML documents by improperly handling clipboard operations for URLs.
Can CVE-2010-1388 affect users on newer macOS versions?
No, CVE-2010-1388 does not affect users running newer versions of macOS that include updated Safari.