Bug 545374 (CVE-2009-2797) - CVE-2009-2797 WebKit, qt: User credentials disclosure via URLs sent in Referer headers
Summary: CVE-2009-2797 WebKit, qt: User credentials disclosure via URLs sent in Refere...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2009-2797
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-12-08 11:48 UTC by Jan Lieskovsky
Modified: 2021-10-19 09:09 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-19 09:09:14 UTC
Embargoed:


Attachments (Terms of Use)

Description Jan Lieskovsky 2009-12-08 11:48:43 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-2797 to
the following vulnerability:

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server. 

References:
-----------
http://support.apple.com/kb/HT3860
http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html
http://secunia.com/advisories/36677

Upstream patch:
---------------
http://trac.webkit.org/changeset/42483


Note You need to log in before you can comment on or make changes to this bug.