Upstream information

CVE-2015-3754 at MITRE

Description

The private-browsing implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent caching of HTTP authentication credentials, which makes it easier for remote attackers to track users via a crafted web site.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
SUSE Bugzilla entry: 1082221 [RESOLVED / FIXED]

SUSE Security Advisories:

    openSUSE-SU-2016:0761-1


SUSE Timeline for this CVE

CVE page created: Mon Aug 17 03:15:32 2015
CVE page last modified: Thu Dec 7 13:08:49 2023