Apple Safari for iPhone and iPod Touch 'Foundation' Unspecified Memory Corruption Vulnerability
BID:27296
Info
Apple Safari for iPhone and iPod Touch 'Foundation' Unspecified Memory Corruption Vulnerability
| Bugtraq ID: | 27296 |
| Class: | Design Error |
| CVE: |
CVE-2008-0035 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2008 12:00AM |
| Updated: | Feb 12 2008 12:06AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1 |
| Not Vulnerable: |
Apple Mac OS X Server 10.5.2 Apple Mac OS X 10.5.2 Apple iPod Touch 1.1.3 Apple iPhone 1.1.3 |
Discussion
Apple Safari for iPhone and iPod Touch 'Foundation' Unspecified Memory Corruption Vulnerability
Apple Safari for iPhone and iPod Touch is prone to a remote code-execution vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may exploit this issue by enticing victims into viewing a maliciously crafted URI.
Successfully exploiting this issue can allow attackers to crash the application or to execute arbitrary code in the context of the affected application.
This issue affects iPhone v1.0 to v1.1.2 and iPod Touch v1.1 to v1.1.2.
Apple Safari for iPhone and iPod Touch is prone to a remote code-execution vulnerability because it fails to adequately sanitize user-supplied input.
An attacker may exploit this issue by enticing victims into viewing a maliciously crafted URI.
Successfully exploiting this issue can allow attackers to crash the application or to execute arbitrary code in the context of the affected application.
This issue affects iPhone v1.0 to v1.1.2 and iPod Touch v1.1 to v1.1.2.
Exploit / POC
Apple Safari for iPhone and iPod Touch 'Foundation' Unspecified Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple Safari for iPhone and iPod Touch 'Foundation' Unspecified Memory Corruption Vulnerability
Solution:
Apple released a security bulletin and fixes to address this issue. The fixes are available via iTunes. Please see the references for more information.
Apple Mac OS X Server 10.5.1
Apple Mac OS X 10.5.1
Solution:
Apple released a security bulletin and fixes to address this issue. The fixes are available via iTunes. Please see the references for more information.
Apple Mac OS X Server 10.5.1
-
Apple SecUpd2008-001PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17381&cat= 1&platform=osx&method=sa/SecUpd2008-001PPC.dmg -
Apple SecUpd2008-001Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17382&cat= 57&platform=osx&method=sa/SecUpd2008-001Univ.dmg
Apple Mac OS X 10.5.1
References
Apple Safari for iPhone and iPod Touch 'Foundation' Unspecified Memory Corruption Vulnerability
References:
References: