First published: Fri Mar 11 2011(Updated: )
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =3.0.4b | |
Apple Mobile Safari | =1.3.0 | |
Apple Mobile Safari | =1.0.3-85.8 | |
Apple Mobile Safari | =2.0.3-417.9.3 | |
Apple Mobile Safari | =1.3.2 | |
Apple Mobile Safari | =2 | |
Apple Mobile Safari | =1.1.1 | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =1.2.2 | |
Apple Mobile Safari | =2.0.1 | |
Apple Mobile Safari | =5.0.1 | |
Apple Mobile Safari | =2.0.3 | |
Apple Mobile Safari | =1.0.3 | |
Apple Mobile Safari | <=5.0.3 | |
Apple Mobile Safari | =2.0.2 | |
Apple Mobile Safari | =1.0.2 | |
Apple Mobile Safari | =3.0.0 | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =1.0 | |
Apple Mobile Safari | =5.0.2 | |
Apple Mobile Safari | =3.0.3b | |
Apple Mobile Safari | =3.1.1 | |
Apple Mobile Safari | =1.3 | |
Apple Mobile Safari | =2.0.3-417.9 | |
Apple Mobile Safari | =1.2.5 | |
Apple Mobile Safari | =2.0.3-417.9.2 | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =2.0 | |
Apple Mobile Safari | =1.2.4 | |
Apple Mobile Safari | =1.0.1 | |
Apple Mobile Safari | =2.0.3-417.8 | |
Apple Mobile Safari | =3.1.2 | |
Apple Mobile Safari | =1.2.1 | |
Apple Mobile Safari | =3.1.0b | |
Apple Mobile Safari | =1.0.3-85.8.1 | |
Apple Mobile Safari | =3.1.0 | |
Apple Mobile Safari | =1.0-beta | |
Apple Mobile Safari | =4.1.1 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =1.0-beta2 | |
Apple Mobile Safari | =1.1 | |
Apple Mobile Safari | =1.3.2-312.5 | |
Apple Mobile Safari | =3.2.2 | |
Apple Mobile Safari | =3.0.0b | |
Apple Mobile Safari | =1.3.1 | |
Apple Mobile Safari | =4.1 | |
Apple Mobile Safari | =2.0.0 | |
Apple Mobile Safari | =3.2.0 | |
Apple Mobile Safari | =1.1.0 | |
Apple Mobile Safari | =3.0.2b | |
Apple Mobile Safari | =1.2 | |
Apple Mobile Safari | =5.0 | |
Apple Mobile Safari | =1.2.0 | |
Apple Mobile Safari | =3.0.1b | |
Apple Mobile Safari | =1.0.0b1 | |
Apple Mobile Safari | =3.2.1 | |
Apple WebKit | ||
Apple Mobile Safari | =3.0 | |
Apple Mobile Safari | =1.0.0 | |
Apple Mobile Safari | =4.1.2 | |
Apple Mobile Safari | =1.2.3 | |
Apple Mobile Safari | =1.3.2-312.6 | |
Apple Mobile Safari | =3 | |
Apple Mobile Safari | =1.0.0b2 | |
iStyle @cosme iPhone OS | =3.0 | |
iStyle @cosme iPhone OS | =3.2 | |
iStyle @cosme iPhone OS | =3.1.3 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =4.0.2 | |
iStyle @cosme iPhone OS | =2.2 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =4.1 | |
iStyle @cosme iPhone OS | =2.0.0 | |
iStyle @cosme iPhone OS | =3.1.2 | |
iStyle @cosme iPhone OS | =3.0.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
iStyle @cosme iPhone OS | =3.1 | |
iStyle @cosme iPhone OS | =1.1.3 | |
iStyle @cosme iPhone OS | =1.1.0 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =2.1 | |
iStyle @cosme iPhone OS | =1.1.5 | |
iStyle @cosme iPhone OS | =4.0.1 | |
iStyle @cosme iPhone OS | =2.1.1 | |
iStyle @cosme iPhone OS | =1.1.4 | |
iStyle @cosme iPhone OS | =1.0.0 | |
iStyle @cosme iPhone OS | =2.0.2 | |
iStyle @cosme iPhone OS | =2.0 | |
iStyle @cosme iPhone OS | =2.0.1 | |
iStyle @cosme iPhone OS | =4.0 | |
iStyle @cosme iPhone OS | <=4.2 | |
iStyle @cosme iPhone OS | =2.2.1 | |
iStyle @cosme iPhone OS | =3.2.1 | |
iStyle @cosme iPhone OS | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0160 is classified as a moderate vulnerability, allowing potential remote credential capture.
To resolve CVE-2011-0160, update your Apple Safari browser to version 5.0.4 or later.
CVE-2011-0160 affects multiple versions of Apple Safari prior to 5.0.4, including earlier versions on iOS.
Yes, CVE-2011-0160 can compromise web security by allowing attackers to intercept HTTP Basic Authentication credentials.
Yes, CVE-2011-0160 poses a risk of credential theft as it enables remote servers to log sensitive authentication headers.