Apple iPhone Mobile Safari Browser Remote Heap Overflow Vulnerability
BID:25002
Info
Apple iPhone Mobile Safari Browser Remote Heap Overflow Vulnerability
| Bugtraq ID: | 25002 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3944 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2007 12:00AM |
| Updated: | Aug 01 2007 12:45PM |
| Credit: | Charlie Miller, Jake Honoroff, and Joshua Mason discovered this issue. |
| Vulnerable: |
Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple iPhone 1 |
| Not Vulnerable: |
Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple iPhone 1.0.1 |
Discussion
Apple iPhone Mobile Safari Browser Remote Heap Overflow Vulnerability
Apple iPhone Mobile Safari Browser is prone to a remote heap-overflow vulnerability that can allow an attacker to gain unauthorized access to a device with administrative privileges.
The researchers responsible for discovering this issue have developed exploit code that can steal sensitive information from a vulnerable device and send it to a remote server. Another proof of concept that exploits the same issue can be used to perform physical actions on the phone such as making a sound or setting the phone to vibrate. The researchers have not yet disclosed the complete details of this vulnerability but will do so as part of a presentation for the BlackHat security conference on August 2, 2007.
This issue also affects Safari on other platforms including Windows and Mac OS X.
Apple iPhone Mobile Safari Browser is prone to a remote heap-overflow vulnerability that can allow an attacker to gain unauthorized access to a device with administrative privileges.
The researchers responsible for discovering this issue have developed exploit code that can steal sensitive information from a vulnerable device and send it to a remote server. Another proof of concept that exploits the same issue can be used to perform physical actions on the phone such as making a sound or setting the phone to vibrate. The researchers have not yet disclosed the complete details of this vulnerability but will do so as part of a presentation for the BlackHat security conference on August 2, 2007.
This issue also affects Safari on other platforms including Windows and Mac OS X.
Exploit / POC
Apple iPhone Mobile Safari Browser Remote Heap Overflow Vulnerability
The researchers who discovered this issue have developed exploit code, but it is not publicly available.
The researchers who discovered this issue have developed exploit code, but it is not publicly available.
Solution / Fix
Apple iPhone Mobile Safari Browser Remote Heap Overflow Vulnerability
Solution:
Apple security advisory APPLE-SA-2007-07-31 iPhone v1.0.1 Update is available; please see the reference section for details.
It should be noted that this update is only available through iTunes and it will not be available through the Software Update application or through the Apple Downloads site. The update can be automatically detected and downloaded by iTunes. The user will be asked to install the update when iPhone is docked.
Apple has also released Safari 3 Beta Update 3.0.3 to address this issue. Please see references for more information.
Apple Safari 3.0.2 Beta
Apple Safari 3.0.2 Beta for Windows
Solution:
Apple security advisory APPLE-SA-2007-07-31 iPhone v1.0.1 Update is available; please see the reference section for details.
It should be noted that this update is only available through iTunes and it will not be available through the Software Update application or through the Apple Downloads site. The update can be automatically detected and downloaded by iTunes. The user will be asked to install the update when iPhone is docked.
Apple has also released Safari 3 Beta Update 3.0.3 to address this issue. Please see references for more information.
Apple Safari 3.0.2 Beta
-
Apple Safari3Beta.dmg
For Mac OS X
http://www.apple.com/safari/download/
Apple Safari 3.0.2 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari+QuickTime for Windows XP or Vista
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
For Windows XP or Vista
http://www.apple.com/safari/download/
References
Apple iPhone Mobile Safari Browser Remote Heap Overflow Vulnerability
References:
References:
- Exploiting the iPhone (Independent Security Evaluators)
- iPhone Product Page (Apple)
- Security Evaluation of Apple�??s iPhone (Independent Security Evaluators)