CVE-2009-2204
Summary
| CVE | CVE-2009-2204 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-08-03 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrated by Charlie Miller at SyScan '09 Singapore. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | 1.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.2 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.3 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.4 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.5 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 2.1 | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple iPhone SMS Application Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| APPLE-SA-2009-07-31-1 iPhone OS 3.0.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| SyScan'10 Singapore :: Day 1 (17 June 2010) | af854a3a-2127-422b-91ae-364da2661108 | www.syscan.org | |
| SecurityTracker.com Archives - Apple iPhone SMS Message Processing Bugs Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| www.blackhat.com/presentations/bh-usa-09/MILLER/BHUSA09-Miller-FuzzingPhone-PA... | af854a3a-2127-422b-91ae-364da2661108 | www.blackhat.com | Exploit |
| About the security content of iPhone OS 3.0.1 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| www.osvdb.org/55687 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Researcher hopes Apple fixes possible iPhone SMS security hole | Security - CNET News | af854a3a-2127-422b-91ae-364da2661108 | news.cnet.com | |
| Apple iPhone SMS Message Decoding Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.