CVE-2016-4590
Description
WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2016-4590 NameCVE-2016-4590 DescriptionWebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed…
CVE-2016-4590
| Name | CVE-2016-4590 |
| Description | WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| webkit2gtk (PTS) | bullseye | 2.44.2-1~deb11u1 | fixed |
| bullseye (security) | 2.50.6-1~deb11u1 | fixed | |
| bookworm, bookworm (security) | 2.50.6-1~deb12u1 | fixed | |
| trixie (security), trixie | 2.52.3-2~deb13u1 | fixed | |
| forky | 2.52.3-2 | fixed | |
| sid | 2.52.4-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| webkit2gtk | source | (unstable) | 2.12.4-1 | unimportant |
OS impact
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.12.4-1 |
| sid | Fixed | 2.12.4-1 |
| forky | Fixed | 2.12.4-1 |
| bullseye | Fixed | 2.12.4-1 |
| bookworm | Fixed | 2.12.4-1 |
macOS Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| — | Not affected | — |
References
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00001.html
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00004.html
- http://packetstormsecurity.com/files/138502/WebKitGTK-SOP-Bypass-Information-Disclosure.html
- http://www.securityfocus.com/archive/1/539295/100/0/threaded
- http://www.securityfocus.com/bid/91835
- http://www.securitytracker.com/id/1036343
- https://support.apple.com/HT206900
- https://support.apple.com/HT206902
- https://security-tracker.debian.org/tracker/CVE-2016-4590
CWEs
CWE-20
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.