Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
BID:36337
Info
Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
| Bugtraq ID: | 36337 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-2207 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2009 12:00AM |
| Updated: | Sep 10 2009 04:31PM |
| Credit: | Clickwise Software and Tony Kavadias |
| Vulnerable: |
Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
Apple iPod Touch 3.1.1 Apple iPhone 3.1 |
Discussion
Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
Apple iPhone and iPod touch are prone to an access-validation vulnerability.
An attacker can exploit this issue to bypass certain security restrictions to obtain sensitive information that may lead to further attacks.
This issue was previously covered in BID 36326 (Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities) but has been given its own record to better document it.
iPhone OS 1.0 through 3.0.1
iPhone OS for iPod touch 1.1 through 3.0
Apple iPhone and iPod touch are prone to an access-validation vulnerability.
An attacker can exploit this issue to bypass certain security restrictions to obtain sensitive information that may lead to further attacks.
This issue was previously covered in BID 36326 (Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities) but has been given its own record to better document it.
iPhone OS 1.0 through 3.0.1
iPhone OS for iPod touch 1.1 through 3.0
Exploit / POC
Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
To exploit this issue, attackers require local interactive access to an affected device.
To exploit this issue, attackers require local interactive access to an affected device.
Solution / Fix
Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
Apple iPhone and iPod Touch MobileMail Component Delete Mail Access Validation Vulnerability
References:
References:
- iPhone Product Page (Apple)
- iPod touch Product Page (Apple)