CVE-2009-1698
Apple WebKit attr() Invalid Attribute Memory Corruption Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
WebKit en Apple Safari anteriores a v4.0 no inicializa un puntero durante el proceso de llamada de función attr Cascading Style Sheets (CSS) con un argumento numérico largo, lo que permite a los atacantes remotos ejecutar arbitrariamente código o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de documentos HTML manipulados.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The specific flaw exists in the handling of attr() functions in a CSS content object. When a large numerical value is passed as the argument to the attr() function, a memory corruption will occur which can be leveraged to execute arbitrary coder under the context of the current user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-05-20 CVE Reserved
- 2009-06-08 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (36)
URL | Tag | Source |
---|---|---|
http://blog.zoller.lu/2009/05/advisory-apple-safari-remote-code.html | X_refsource_misc | |
http://osvdb.org/55006 | Vdb Entry | |
http://secunia.com/advisories/35588 | Third Party Advisory | |
http://secunia.com/advisories/36057 | Third Party Advisory | |
http://secunia.com/advisories/36062 | Third Party Advisory | |
http://secunia.com/advisories/36790 | Third Party Advisory | |
http://secunia.com/advisories/37746 | Third Party Advisory | |
http://secunia.com/advisories/43068 | Third Party Advisory | |
http://support.apple.com/kb/HT3639 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/504173/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/504295/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/35318 | Vdb Entry | |
http://www.vupen.com/english/advisories/2009/1621 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0212 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9484 | Signature |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/35260 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html | 2022-08-09 | |
http://securitytracker.com/id?1022345 | 2022-08-09 | |
http://support.apple.com/kb/HT3613 | 2022-08-09 | |
http://www.vupen.com/english/advisories/2009/1522 | 2022-08-09 | |
http://www.zerodayinitiative.com/advisories/ZDI-09-032 | 2022-08-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.0.0 Search vendor "Apple" for product "Iphone Os" and version "1.0.0" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.0.1 Search vendor "Apple" for product "Iphone Os" and version "1.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.0.2 Search vendor "Apple" for product "Iphone Os" and version "1.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.0 Search vendor "Apple" for product "Iphone Os" and version "1.1.0" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.1 Search vendor "Apple" for product "Iphone Os" and version "1.1.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.2 Search vendor "Apple" for product "Iphone Os" and version "1.1.2" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.3 Search vendor "Apple" for product "Iphone Os" and version "1.1.3" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.4 Search vendor "Apple" for product "Iphone Os" and version "1.1.4" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.5 Search vendor "Apple" for product "Iphone Os" and version "1.1.5" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0 Search vendor "Apple" for product "Iphone Os" and version "2.0" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.0 Search vendor "Apple" for product "Iphone Os" and version "2.0.0" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.1 Search vendor "Apple" for product "Iphone Os" and version "2.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.2 Search vendor "Apple" for product "Iphone Os" and version "2.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1 Search vendor "Apple" for product "Iphone Os" and version "2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1.1 Search vendor "Apple" for product "Iphone Os" and version "2.1.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2 Search vendor "Apple" for product "Iphone Os" and version "2.2" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2.1 Search vendor "Apple" for product "Iphone Os" and version "2.2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.0 Search vendor "Apple" for product "Iphone Os" and version "1.1.0" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.1 Search vendor "Apple" for product "Iphone Os" and version "1.1.1" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.2 Search vendor "Apple" for product "Iphone Os" and version "1.1.2" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.3 Search vendor "Apple" for product "Iphone Os" and version "1.1.3" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.4 Search vendor "Apple" for product "Iphone Os" and version "1.1.4" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 1.1.5 Search vendor "Apple" for product "Iphone Os" and version "1.1.5" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0 Search vendor "Apple" for product "Iphone Os" and version "2.0" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.0 Search vendor "Apple" for product "Iphone Os" and version "2.0.0" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.1 Search vendor "Apple" for product "Iphone Os" and version "2.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.0.2 Search vendor "Apple" for product "Iphone Os" and version "2.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1 Search vendor "Apple" for product "Iphone Os" and version "2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.1.1 Search vendor "Apple" for product "Iphone Os" and version "2.1.1" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2 Search vendor "Apple" for product "Iphone Os" and version "2.2" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | 2.2.1 Search vendor "Apple" for product "Iphone Os" and version "2.2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Ipod Touch Search vendor "Apple" for product "Ipod Touch" | * | - |
Affected
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | <= 3.2.2 Search vendor "Apple" for product "Safari" and version " <= 3.2.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0 Search vendor "Apple" for product "Safari" and version "2.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.0 Search vendor "Apple" for product "Safari" and version "2.0.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.1 Search vendor "Apple" for product "Safari" and version "2.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.2 Search vendor "Apple" for product "Safari" and version "2.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.8 |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.9 |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.9.2 |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.9.3 |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.4 Search vendor "Apple" for product "Safari" and version "2.0.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0 Search vendor "Apple" for product "Safari" and version "3.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.0 Search vendor "Apple" for product "Safari" and version "3.0.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.0b Search vendor "Apple" for product "Safari" and version "3.0.0b" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.1 Search vendor "Apple" for product "Safari" and version "3.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.1 Search vendor "Apple" for product "Safari" and version "3.0.1" | beta |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.1b Search vendor "Apple" for product "Safari" and version "3.0.1b" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.2 Search vendor "Apple" for product "Safari" and version "3.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.2b Search vendor "Apple" for product "Safari" and version "3.0.2b" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.3 Search vendor "Apple" for product "Safari" and version "3.0.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.3b Search vendor "Apple" for product "Safari" and version "3.0.3b" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.4 Search vendor "Apple" for product "Safari" and version "3.0.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.4b Search vendor "Apple" for product "Safari" and version "3.0.4b" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.0 Search vendor "Apple" for product "Safari" and version "3.1.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.0b Search vendor "Apple" for product "Safari" and version "3.1.0b" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.1 Search vendor "Apple" for product "Safari" and version "3.1.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.2 Search vendor "Apple" for product "Safari" and version "3.1.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2.0 Search vendor "Apple" for product "Safari" and version "3.2.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2.1 Search vendor "Apple" for product "Safari" and version "3.2.1" | - |
Affected
|