Secunia Security Advisory - Cesar Cerrudo has discovered a vulnerability in Apple Safari, which can be exploited by malicious people to disclose potentially sensitive information.
297b8f6413cd5d835ad3aad5e092196957304ab8e3423258566dacce0560e5b8
----------------------------------------------------------------------
Secunia integrated with Microsoft WSUS
http://secunia.com/blog/71/
----------------------------------------------------------------------
TITLE:
Apple Safari Stylesheet Redirection Information Disclosure
SECUNIA ADVISORY ID:
SA37931
VERIFY ADVISORY:
http://secunia.com/advisories/37931/
DESCRIPTION:
Cesar Cerrudo has discovered a vulnerability in Apple Safari, which
can be exploited by malicious people to disclose potentially
sensitive information.
The vulnerability is caused due to the application following
redirects for stylesheets and allowing to read the target URL. This
can be exploited on sites that use redirects to URLs containing
potentially sensitive information e.g. within the query string.
This is related to vulnerability #8 in:
SA28758
NOTE: This does not affect redirects to URLs using HTTPS.
The vulnerability is confirmed in version 4.0.4 on Windows. Other
versions may also be affected.
SOLUTION:
Do not browse untrusted sites while accessing other sites with
potentially sensitive information in the URL.
PROVIDED AND/OR DISCOVERED BY:
Cesar Cerrudo
ORIGINAL ADVISORY:
http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html
OTHER REFERENCES:
SA28758:
http://secunia.com/advisories/28758/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
private users keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------