CVE-2009-1694
EPSS 0.71%
Description
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."
How to fix CVE-2009-1694
To remediate CVE-2009-1694, upgrade the affected package to a fixed version below.
- Debian/qt4-x11—upgrade to 4:4.6.2-4 or later
Is CVE-2009-1694 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4:4.6.2-4