CVE-2010-2973
Summary
| CVE | CVE-2010-2973 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-05 18:17:58 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple iOS CFF Font Parsing and IOSurface Integer Overflow - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Apple iOS for iPhone/iPad/iPod touch Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| APPLE-SA-2010-08-11-2 iOS 3.2.2 Update for iPad | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Apple iOS pdf Jailbreak Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| About the security content of the iOS 4.0.2 Update for iPhone and iPod touch | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| osvdb.org/66827 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| APPLE-SA-2010-08-11-1 iOS 4.0.2 Update for iPhone and iPod touch | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of the iOS 3.2.2 Update for iPad | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.