Vulnerability Name:

CVE-2009-0123 (CCN-47917)

Assigned:2009-01-11
Published:2009-01-11
Updated:2017-08-08
Summary:Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.
Note: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N)
5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-noinfo
CWE-200
Vulnerability Consequences:Obtain Information
References:Source: CCN
Type: Brian Mastenbrook Web site
Brian Mastenbrook: Disclosure of information vulnerability in Safari

Source: MISC
Type: UNKNOWN
http://brian.mastenbrook.net/display/27

Source: MITRE
Type: CNA
CVE-2009-0123

Source: MISC
Type: UNKNOWN
http://isc.sans.org/diary.html?storyid=5689

Source: CCN
Type: SA33458
Apple Safari RSS Feed URL Handling Information Disclosure

Source: SECUNIA
Type: UNKNOWN
33458

Source: CCN
Type: SECTRACK ID: 1021581
Safari RSS Feed Bug Discloses Files to Remote Users

Source: CCN
Type: Apple Security Update 2009-001
About the security content of Security Update 2009-001

Source: CCN
Type: Apple Web site
About the security content of Safari 3.2.2 for Windows

Source: CCN
Type: Apple Safari Web site
Apple - Safari

Source: CCN
Type: OSVDB ID: 51405
Apple Safari RSS Feed URL Handling Information Disclosure

Source: BID
Type: UNKNOWN
33234

Source: CCN
Type: BID-33234
Apple Safari 'feed:' URI Multiple Input Validation Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1021581

Source: XF
Type: UNKNOWN
safari-rss-feed-info-disclosure(47917)

Source: XF
Type: UNKNOWN
safari-rss-feed-info-disclosure(47917)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apple:safari:*:*:*:*:*:*:*:*
  • AND
  • cpe:/o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apple:safari:3.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:3.0.4_beta:*:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:3.1:*:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:3.0.1:beta:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:3:*:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:3.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:apple:safari:3.1.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple safari *
    apple mac os x 10.5
    microsoft windows *
    apple safari 3.0.3
    apple safari 3.0.4_beta
    apple safari 3.1
    apple safari 3.0.1 beta
    apple safari 3
    apple safari 3.1.1
    apple safari 3.1.2