Apple iPhone and iPod Touch Prior to Version 2.0 Multiple Remote Vulnerabilities
BID:30186
Info
Apple iPhone and iPod Touch Prior to Version 2.0 Multiple Remote Vulnerabilities
| Bugtraq ID: | 30186 |
| Class: | Unknown |
| CVE: |
CVE-2008-1590 CVE-2008-2317 CVE-2008-2303 CVE-2008-1589 CVE-2008-1588 CVE-2009-0070 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2008 12:00AM |
| Updated: | Jun 09 2009 04:49PM |
| Credit: | Hiromitsu Takagi, SkyLined of Google, Peter Vreudegnhil working with the TippingPoint Zero Day Initiative, Jonathan Rom of Radware and the vendor reported these issues. |
| Vulnerable: |
Apple Safari 3.2.3 for Windows Apple Safari 3.2.3 Apple Safari 3.2.2 for Windows Apple Safari 3.1.2 for Windows Apple Safari 3.1.2 Apple Safari 3.1.1 for Windows Apple Safari 3.1.1 Apple Safari 3.0.4 Beta for Windows Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple Safari 3.0.1 Beta for Windows Apple Safari 3.0.1 Beta Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.2 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari 4 Beta Apple Safari 3.2 Apple Safari 3.1 for Windows Apple Safari 3.1 Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Safari 3 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 1.1 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 1.1 Apple iPhone 1 |
| Not Vulnerable: |
Apple Safari 4 for Windows Apple Safari 4 Apple iPod Touch 2.0 Apple iPhone 2.0 |
Discussion
Apple iPhone and iPod Touch Prior to Version 2.0 Multiple Remote Vulnerabilities
Apple iPhone and iPod touch are prone to multiple remote vulnerabilities:
1. A vulnerability that may allow users to spoof websites.
2. An information-disclosure vulnerability.
3. A buffer-overflow vulnerability.
4. Two memory-corruption vulnerabilities.
Successfully exploiting these issues may allow attackers to execute arbitrary code, crash the affected application, obtain sensitive information, or direct unsuspecting victims to a spoofed site; other attacks are also possible.
These issues affect iPhone 1.0 through 1.1.4 and iPod touch 1.1 through 1.1.4.
Apple iPhone and iPod touch are prone to multiple remote vulnerabilities:
1. A vulnerability that may allow users to spoof websites.
2. An information-disclosure vulnerability.
3. A buffer-overflow vulnerability.
4. Two memory-corruption vulnerabilities.
Successfully exploiting these issues may allow attackers to execute arbitrary code, crash the affected application, obtain sensitive information, or direct unsuspecting victims to a spoofed site; other attacks are also possible.
These issues affect iPhone 1.0 through 1.1.4 and iPod touch 1.1 through 1.1.4.
Exploit / POC
Apple iPhone and iPod Touch Prior to Version 2.0 Multiple Remote Vulnerabilities
Some of these issues may not require specific exploit code and may be trivial to exploit.
The following example exploit is available for the JavaScript index issue (CVE-2008-2303):
Some of these issues may not require specific exploit code and may be trivial to exploit.
The following example exploit is available for the JavaScript index issue (CVE-2008-2303):
Solution / Fix
Apple iPhone and iPod Touch Prior to Version 2.0 Multiple Remote Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Apple Safari 3
Apple Safari 3 Beta for Windows
Apple Safari 3.1 for Windows
Apple Safari 4 Beta
Apple Safari 3.2
Apple Safari 3.1
Apple Safari 3 Beta
Apple Safari 1.0
Apple Safari 1.1
Apple Safari 1.2
Apple Safari 1.2.1
Apple Safari 1.2.2
Apple Safari 1.2.3
Apple Safari 1.3
Apple Safari 1.3.1
Apple Safari 1.3.2
Apple Safari 2.0.1
Apple Safari 2.0.2
Apple Safari 2.0.3
Apple Safari 2.0.4
Apple Safari 3.0.1 Beta
Apple Safari 3.0.1 Beta for Windows
Apple Safari 3.0.2 Beta
Apple Safari 3.0.2 Beta for Windows
Apple Safari 3.0.3 Beta
Apple Safari 3.0.3 Beta for Windows
Apple Safari 3.0.4 Beta for Windows
Apple Safari 3.1.1
Apple Safari 3.1.1 for Windows
Apple Safari 3.1.2 for Windows
Apple Safari 3.1.2
Apple Safari 3.2.2 for Windows
Apple Safari 3.2.3
Apple Safari 3.2.3 for Windows
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Apple Safari 3
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 4 Beta
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.1
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3 Beta
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.0
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.3.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.3.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.4
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.1 Beta
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.1 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.0.2 Beta
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.2 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.0.3 Beta
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.3 Beta for Windows
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.4 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1.1
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.1.1 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1.2 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1.2
-
Apple Safari 3.2 for Leopard
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22162&cat= 1&platform=osx&method=sa/ -
Apple Safari 3.2 for Tiger
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22157&cat= 1&platform=osx&method=sa/ -
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.2.2 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.2.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.2.3 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
References
Apple iPhone and iPod Touch Prior to Version 2.0 Multiple Remote Vulnerabilities
References:
References: