An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation in the "WebKit" component. It allows remote attackers to execute arbitrary code or spoof a bookmark by leveraging mishandling of links during drag-and-drop actions.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/97129 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038137 | |
https://support.apple.com/HT207600 | Vendor Advisory |
https://support.apple.com/HT207617 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apple
Published: 2017-04-02T01:36:00
Updated: 2017-07-11T09:57:01
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2378
JSON object: View
NVD Information
Status : Modified
Published: 2017-04-02T01:59:00.310
Modified: 2017-07-12T01:29:09.083
Link: CVE-2017-2378
JSON object: View
Redhat Information
No data.
CWE