ISOMAN

CVE

CVE-2015-3752

The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.

Severity
MEDIUM
CVSS
5
Published
Modified

Linked Releases

References

  1. http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html
  2. http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html
  3. http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html
  4. http://www.securityfocus.com/bid/76341
  5. http://www.securitytracker.com/id/1033274
  6. http://www.ubuntu.com/usn/USN-2937-1
  7. https://support.apple.com/kb/HT205030
  8. https://support.apple.com/kb/HT205033
  9. http://lists.apple.com/archives/security-announce/2015/Aug/msg00000.html
  10. http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html
  11. http://lists.opensuse.org/opensuse-updates/2016-03/msg00132.html
  12. http://www.securityfocus.com/bid/76341
  13. http://www.securitytracker.com/id/1033274
  14. http://www.ubuntu.com/usn/USN-2937-1
  15. https://support.apple.com/kb/HT205030
  16. https://support.apple.com/kb/HT205033