CVE-2009-1699
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 29.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 29.10% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- apple/safari · apple/iphone os · canonical/ubuntu linux · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlMailing List
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlBroken Link, Mailing List, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List
- http://osvdb.org/54972Broken Link
- http://scary.beasts.org/security/CESA-2009-006.htmlExploit
- http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.htmlExploit
- http://secunia.com/advisories/35379Broken Link, Vendor Advisory
- http://secunia.com/advisories/43068Broken Link
- http://support.apple.com/kb/HT3613Patch, Vendor Advisory
- http://support.apple.com/kb/HT3639Vendor Advisory
- http://www.securityfocus.com/bid/35260Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35321Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-857-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/1522Broken Link, Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1621Broken Link
- http://www.vupen.com/english/advisories/2011/0212Broken Link
- https://www.exploit-db.com/exploits/8907Exploit, Third Party Advisory, VDB Entry
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlMailing List
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlBroken Link, Mailing List, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List
- http://osvdb.org/54972Broken Link
- http://scary.beasts.org/security/CESA-2009-006.htmlExploit
- http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.htmlExploit
- http://secunia.com/advisories/35379Broken Link, Vendor Advisory
- http://secunia.com/advisories/43068Broken Link
- http://support.apple.com/kb/HT3613Patch, Vendor Advisory
- http://support.apple.com/kb/HT3639Vendor Advisory
- http://www.securityfocus.com/bid/35260Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35321Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-857-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.