CVE-2009-2058

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
15/06/2009
Last modified:
09/04/2025

Description

Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 3.2.2 (including)