CVE-2012-3715: Medium severity safari vulnerability
Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a paste into the address bar, which allows user-assisted remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3715?
The severity of CVE-2012-3715 is considered to be moderate, as it allows potential information disclosure under specific conditions.
How do I fix CVE-2012-3715?
To resolve CVE-2012-3715, users should update to Apple Safari version 6.0.1 or later.
What does CVE-2012-3715 exploit?
CVE-2012-3715 exploits a behavior in Apple Safari that causes HTTP requests to be made for HTTPS URIs from the address bar after a paste action.
How can I mitigate the effects of CVE-2012-3715?
To mitigate CVE-2012-3715, you can avoid pasting HTTPS URLs into the Safari address bar until you have updated to at least version 6.0.1.
Which versions of Safari are affected by CVE-2012-3715?
CVE-2012-3715 affects all versions of Apple Safari prior to 6.0.1.