CVE-2010-2973
Summary
| CVE | CVE-2010-2973 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-05 18:17:00 UTC |
| Updated | 2022-08-09 13:49:00 UTC |
| Description | Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Apple | Ipad | All | All | All | All |
| Hardware | Apple | Ipad | All | All | All | All |
| Hardware | Apple | Iphone | All | All | All | All |
| Hardware | Apple | Iphone | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Iphone Os | 4.0 | All | All | All |
| Operating System | Apple | Iphone Os | 4.0 | - | iphone | All |
| Operating System | Apple | Iphone Os | 4.0 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 4.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 4.0.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 4.0.1 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 4.0 | All | All | All |
| Operating System | Apple | Iphone Os | 4.0 | - | iphone | All |
| Operating System | Apple | Iphone Os | 4.0 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 4.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 4.0.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 4.0.1 | - | ipodtouch | All |
| Hardware | Apple | Ipod Touch | All | All | All | All |
| Hardware | Apple | Ipod Touch | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple iOS for iPhone/iPad/iPod touch Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| About the security content of the iOS 4.0.2 Update for iPhone and iPod touch | CONFIRM | support.apple.com | |
| APPLE-SA-2010-08-11-1 iOS 4.0.2 Update for iPhone and iPod touch | APPLE | lists.apple.com | |
| About the security content of the iOS 3.2.2 Update for iPad | CONFIRM | support.apple.com | |
| Apple iOS pdf Jailbreak Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit |
| APPLE-SA-2010-08-11-2 iOS 3.2.2 Update for iPad | APPLE | lists.apple.com | |
| Apple iOS CFF Font Parsing and IOSurface Integer Overflow - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| 66827 | OSVDB | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.