Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
BID:36335
Info
Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
| Bugtraq ID: | 36335 |
| Class: | Unknown |
| CVE: |
CVE-2009-2796 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2009 12:00AM |
| Updated: | Sep 10 2009 04:21PM |
| Credit: | Abraham Vegh |
| Vulnerable: |
Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
Apple iPod Touch 3.1.1 Apple iPhone 3.1 |
Discussion
Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
Apple iPhone and iPod touch are prone to an information-disclosure vulnerability in the UIKit component.
Successful exploits may allow attackers with physical access to an affected device to obtain password data. Information harvested may aid in launching further attacks.
This issue was previously covered in BID 36326 (Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities) but has been given its own record to better document it.
This issue affects the following:
iPhone OS 1.0 through 3.0.1
iPhone OS for iPod touch 1.1 through 3.0
Apple iPhone and iPod touch are prone to an information-disclosure vulnerability in the UIKit component.
Successful exploits may allow attackers with physical access to an affected device to obtain password data. Information harvested may aid in launching further attacks.
This issue was previously covered in BID 36326 (Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities) but has been given its own record to better document it.
This issue affects the following:
iPhone OS 1.0 through 3.0.1
iPhone OS for iPod touch 1.1 through 3.0
Exploit / POC
Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
To exploit this issue, an attacker requires physical access to an affected device.
To exploit this issue, an attacker requires physical access to an affected device.
Solution / Fix
Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
Solution:
The vendor released an advisory and fixes. Please see the references for details.
Solution:
The vendor released an advisory and fixes. Please see the references for details.
References
Apple iPhone and iPod touch UIKit Deleted Password Character Information Disclosure Vulnerability
References:
References:
- iPhone Product Page (Apple)
- iPod touch Product Page (Apple)