Lucene search

K
jvnJapan Vulnerability NotesJVN:45442753
HistorySep 25, 2014 - 12:00 a.m.

JVN#45442753: Safari issue in handling application cache

2014-09-2500:00:00
Japan Vulnerability Notes
jvn.jp
23

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

76.1%

Safari contains an issue in the handling of application cache where contents that were cached when the private browsing function is turned off may be used after the private browsing function is turned on.

Impact

After a website is visited when the private browsing function is turned off and the site is visited again after the private browsing function is turned on, the website may be able to determine that the same user visited the website.

Solution

Update the software
Update to the latest version according to the information provided by the developer.

Products Affected

  • Safari versions prior to 6.2
  • Safari versions prior to 7.1

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

76.1%