CVE-2009-2816

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

References

http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html

http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html

http://osvdb.org/59940

http://osvdb.org/59967

http://secunia.com/advisories/37346

http://secunia.com/advisories/37358

http://secunia.com/advisories/37393

http://secunia.com/advisories/37397

http://secunia.com/advisories/43068

http://support.apple.com/kb/HT3949

http://support.apple.com/kb/HT4225

http://www.securityfocus.com/bid/36997

http://www.securitytracker.com/id?1023165

http://www.vupen.com/english/advisories/2009/3217

http://www.vupen.com/english/advisories/2009/3233

http://www.vupen.com/english/advisories/2011/0212

https://bugzilla.redhat.com/show_bug.cgi?id=525789

https://exchange.xforce.ibmcloud.com/vulnerabilities/54239

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6516

https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00545.html

https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00549.html

Details

Source: MITRE

Published: 2009-11-13

Updated: 2017-09-19

Type: CWE-352

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

AND

OR

cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0:beta:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0:beta2:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.0b1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.0b2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.1.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.1.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.2.5:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:1.3.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.8:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.9:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.9.2:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3:417.9.3:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.3_417.9.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0.4_419.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:2.0_pre:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.0b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.1:beta:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.1b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.2b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.3b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.4:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.4_beta:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.0.4b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.0b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.1.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:3.2.3:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.0:beta:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*

cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:google:chrome:0.2.149.27:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.2.149.29:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.2.149.30:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.2.152.1:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.2.153.1:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.3.154.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.3.154.3:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.4.154.18:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.4.154.22:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.4.154.31:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:0.4.154.33:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.36:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.39:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.42:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.43:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.46:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.48:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.52:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.53:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.59:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:1.0.154.65:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.156.1:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.157.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.157.2:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.158.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.159.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.169.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.169.1:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.170.0:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.2:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.8:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.27:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.28:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.30:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.31:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.33:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.37:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:2.0.172.38:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:3.0.182.2:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:3.0.190.2:*:*:*:*:*:*:*

cpe:2.3:a:google:chrome:3.0.193.2:beta:*:*:*:*:*:*

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to 3.0.195.21 (inclusive)

Tenable Plugins

View all (12 total)

IDNameProductFamilySeverity
75629openSUSE Security Update : libwebkit (openSUSE-SU-2011:0024-1)NessusSuSE Local Security Checks
critical
53764openSUSE Security Update : libwebkit (openSUSE-SU-2011:0024-1)NessusSuSE Local Security Checks
critical
5578Apple iOS < 4.0 Multiple VulnerabilitiesNessus Network MonitorMobile Devices
critical
42807Fedora 11 : qt-4.5.3-9.fc11 (2009-11491)NessusFedora Local Security Checks
high
42804Fedora 10 : qt-4.5.3-9.fc10 (2009-11488)NessusFedora Local Security Checks
high
42803Fedora 12 : qt-4.5.3-9.fc12 (2009-11487)NessusFedora Local Security Checks
high
5234Google Chrome < 3.0.195.33 Security Bypass Vulnerability.Nessus Network MonitorWeb Clients
medium
42798Google Chrome < 3.0.195.33 Multiple VulnerabilitiesNessusWindows
medium
42478Safari < 4.0.4 Multiple VulnerabilitiesNessusWindows
high
42477Mac OS X : Apple Safari < 4.0.4NessusMacOS X Local Security Checks
high
801003Safari < 4.0.4 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
5232Safari < 4.0.4 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium