The tabbed browsing feature in Apple Safari 3 before Beta...
Vulnerability Description
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4692
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/26444
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00003.html
- http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38460
- http://docs.info.apple.com/article.html?artnum=307041
- http://www.vupen.com/english/advisories/2007/3868
- http://secunia.com/advisories/27643
- http://osvdb.org/40662
- http://www.securityfocus.com/bid/26447
- http://www.us-cert.gov/cas/techalerts/TA07-319A.html
More from apple
View All →Affected Vendor
apple
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.