Safari < 3.2.2 Multiple Vulnerabilities

high Log Correlation Engine Plugin ID 801011


The remote host contains a web browser that is vulnerable to multiple attack vectors.


The version of Safari installed on the remote Windows host is earlier than 3.2.2. Such versions reportedly have multiple vulnerabilities :

- Multiple input validation issues in their handling of 'feed: ' URLs, which could be abused to execute arbitrary JavaScript code in the local security zone. (CVE-2009-0137)

- A cached certificate is not required before displaying a lock icon for a HTTPS web site. This allows a man-in-the-middle attacker to present the user with spoofed web pages over HTTPS that appear to be from a legitimate source. (CVE-2009-2072)

- The browser processes a 3xxx HTTP CONNECT before a successful SSL handshake, which could allow a man-in-the-midddle attacker to execute arbitrary script code in the context of a HTTPS site. (CVE-2009-2062)


Upgrade to version 3.2.2 or higher.

See Also

Plugin Details

Severity: High

ID: 801011

Family: Web Clients

Nessus ID: 35687

Risk Information


Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Reference Information

CVE: CVE-2009-0137, CVE-2009-2061, CVE-2009-2062, CVE-2009-2063, CVE-2009-2069, CVE-2009-2070, CVE-2009-2072, CVE-2009-2071, CVE-2009-0123

BID: 35411, 35412, 33234