Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities
BID:31092
Info
Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities
| Bugtraq ID: | 31092 |
| Class: | Unknown |
| CVE: |
CVE-2008-3632 CVE-2008-3612 CVE-2008-3631 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2008 12:00AM |
| Updated: | Jun 09 2009 04:59PM |
| Credit: | Nicolas Seriot of Sen:te, Bryce Cogswell, and the vendor |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Apple Safari 3.2.3 for Windows Apple Safari 3.2.3 Apple Safari 3.2.2 for Windows Apple Safari 3.1.2 for Windows Apple Safari 3.1.2 Apple Safari 3.1.1 for Windows Apple Safari 3.1.1 Apple Safari 3.0.4 Beta for Windows Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple Safari 3.0.1 Beta for Windows Apple Safari 3.0.1 Beta Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.2 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari 3.2 Apple Safari 3.1 for Windows Apple Safari 3.1 Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Safari 3 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 2.0 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 2.0 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
Apple Safari 4 for Windows Apple Safari 4 Apple iPod Touch 2.1 Apple iPhone 2.1 |
Discussion
Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities
Apple iPod touch and iPhone are prone to multiple remote vulnerabilities:
1. A vulnerability that may allow users to spoof websites.
2. An information-disclosure vulnerability.
3. A remote code-execution vulnerability.
Successfully exploiting these issues may allow attackers to execute arbitrary code, crash the affected application, obtain sensitive information, or direct unsuspecting victims to a spoofed site; other attacks are also possible.
These issues affect versions prior to iPod touch 2.1 and iPhone 2.1.
Apple iPod touch and iPhone are prone to multiple remote vulnerabilities:
1. A vulnerability that may allow users to spoof websites.
2. An information-disclosure vulnerability.
3. A remote code-execution vulnerability.
Successfully exploiting these issues may allow attackers to execute arbitrary code, crash the affected application, obtain sensitive information, or direct unsuspecting victims to a spoofed site; other attacks are also possible.
These issues affect versions prior to iPod touch 2.1 and iPhone 2.1.
Exploit / POC
Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Solution / Fix
Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Apple Safari 3
Ubuntu Ubuntu Linux 8.10 powerpc
Ubuntu Ubuntu Linux 8.10 i386
Apple Safari 3 Beta for Windows
Apple Safari 3.1 for Windows
Ubuntu Ubuntu Linux 8.10 lpia
Apple Safari 3.1
Apple Safari 3.2
Ubuntu Ubuntu Linux 8.10 sparc
Ubuntu Ubuntu Linux 8.10 amd64
Apple Safari 3 Beta
Apple Safari 1.0
Apple Safari 1.1
Apple Safari 1.2
Apple Safari 1.2.1
Apple Safari 1.2.2
Apple Safari 1.2.3
Apple Safari 1.3
Apple Safari 1.3.1
Apple Safari 1.3.2
Apple Safari 2.0.1
Apple Safari 2.0.2
Apple Safari 2.0.3
Apple Safari 2.0.4
Apple Safari 3.0.1 Beta
Apple Safari 3.0.1 Beta for Windows
Apple Safari 3.0.2 Beta
Apple Safari 3.0.2 Beta for Windows
Apple Safari 3.0.3 Beta
Apple Safari 3.0.3 Beta for Windows
Apple Safari 3.0.4 Beta for Windows
Apple Safari 3.1.1
Apple Safari 3.1.1 for Windows
Apple Safari 3.1.2 for Windows
Apple Safari 3.1.2
Apple Safari 3.2.2 for Windows
Apple Safari 3.2.3
Apple Safari 3.2.3 for Windows
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Apple Safari 3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Ubuntu Ubuntu Linux 8.10 powerpc
-
Ubuntu libwebkit-1.0-1-dbg_1.0.1-2ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1-dbg_1.0.1-2 ubuntu0.1_powerpc.deb -
Ubuntu libwebkit-1.0-1_1.0.1-2ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1_1.0.1-2ubun tu0.1_powerpc.deb -
Ubuntu libwebkit-dev_1.0.1-2ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0 .1-2ubuntu0.1_all.deb
Ubuntu Ubuntu Linux 8.10 i386
-
Ubuntu libwebkit-1.0-1-dbg_1.0.1-2ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1-d bg_1.0.1-2ubuntu0.1_i386.deb -
Ubuntu libwebkit-1.0-1_1.0.1-2ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1_1 .0.1-2ubuntu0.1_i386.deb -
Ubuntu libwebkit-dev_1.0.1-2ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0 .1-2ubuntu0.1_all.deb
Apple Safari 3 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Ubuntu Ubuntu Linux 8.10 lpia
-
Ubuntu libwebkit-1.0-1-dbg_1.0.1-2ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1-dbg_1.0.1-2 ubuntu0.1_lpia.deb -
Ubuntu libwebkit-1.0-1_1.0.1-2ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1_1.0.1-2ubun tu0.1_lpia.deb -
Ubuntu libwebkit-dev_1.0.1-2ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0 .1-2ubuntu0.1_all.deb
Apple Safari 3.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Ubuntu Ubuntu Linux 8.10 sparc
-
Ubuntu libwebkit-1.0-1-dbg_1.0.1-2ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1-dbg_1.0.1-2 ubuntu0.1_sparc.deb -
Ubuntu libwebkit-1.0-1_1.0.1-2ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1_1.0.1-2ubun tu0.1_sparc.deb -
Ubuntu libwebkit-dev_1.0.1-2ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0 .1-2ubuntu0.1_all.deb
Ubuntu Ubuntu Linux 8.10 amd64
-
Ubuntu libwebkit-1.0-1-dbg_1.0.1-2ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1-d bg_1.0.1-2ubuntu0.1_amd64.deb -
Ubuntu libwebkit-1.0-1_1.0.1-2ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1_1 .0.1-2ubuntu0.1_amd64.deb -
Ubuntu libwebkit-dev_1.0.1-2ubuntu0.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0 .1-2ubuntu0.1_all.deb
Apple Safari 3 Beta
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.0
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.2.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.3.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 1.3.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 2.0.4
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.1 Beta
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.1 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.0.2 Beta
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.2 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.0.3 Beta
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.3 Beta for Windows
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.0.4 Beta for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1.1
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.1.1 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1.2 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.1.2
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.2.2 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
Apple Safari 3.2.3
-
Apple Safari4.0Leo.dmg
http://www.apple.com/safari/download/ -
Apple Safari4.0Ti.dmg
http://www.apple.com/safari/download/
Apple Safari 3.2.3 for Windows
-
Apple SafariQuickTimeSetup.exe
Safari4
http://www.apple.com/safari/download/ -
Apple SafariSetup.exe
Safari4
http://www.apple.com/safari/download/
References
Apple iPod Touch/iPhone Prior to Version 2.1 Multiple Remote Vulnerabilities
References:
References:
- iPod touch Product Page (Apple)