Apple Safari WebKit page loading information leakage Vulnerability
Apple Safari WebKit page loading information leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Apple Safari <8.0.8
Apple Safari <7.1.8
Apple Safari <6.2.8
Description:
Bugtraq id: 76339
CVE (CAN) ID: CVE-2015-3754
Safari is the browser in Mac OS X, the latest operating system of Apple Computer. It uses KDE's KHTML as the core of browser computing.
In versions earlier than Apple Safari 6.2.8, earlier than 7.1.8, and earlier than 8.0.8, HTTP Authentication creden are cached in private browser implementations of WebKit, which allows remote attackers to construct websites, this vulnerability is used to track users.
<* Source: dongw.kim (@ kid1ng)
*>
Suggestion:
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://support.apple.com/kb/HT205033
Http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html
This article permanently updates the link address: