Name | CVE-2009-2199 |
Description | Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
qt4-x11 (PTS) | jessie, jessie (lts) | 4:4.8.6+git64-g5dc8b2b+dfsg-3+deb8u5 | fixed |
stretch (security) | 4:4.8.7+dfsg-11+deb9u3 | fixed | |
stretch (lts), stretch | 4:4.8.7+dfsg-11+deb9u4 | fixed | |
buster (security), buster, buster (lts) | 4:4.8.7+dfsg-18+deb10u2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
kdelibs | source | (unstable) | (not affected) | |||
qt4-x11 | source | (unstable) | (not affected) | |||
webkit | source | (unstable) | (not affected) |
- webkit <not-affected> (problem with look-alike character rendering with mac-specific fonts)