Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
BID:36342
Info
Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
| Bugtraq ID: | 36342 |
| Class: | Design Error |
| CVE: |
CVE-2009-2794 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 09 2009 12:00AM |
| Updated: | Sep 09 2009 11:31PM |
| Credit: | Allan Steven, Robert Duran, Jeff Beckham of PepsiCo, Joshua Levitsky, Michael Breton of Intel Corporation, Mike Karban of Edward Jones, and Steve Moriarty of Agilent Technologies |
| Vulnerable: |
Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 1.1.4 Apple iPod Touch 1.1.3 Apple iPod Touch 1.1.2 Apple iPod Touch 1.1.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPod Touch 1.1 Apple iPod Touch 0 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 1.1.4 Apple iPhone 1.1.3 Apple iPhone 1.1.2 Apple iPhone 1.1.1 Apple iPhone 1.0.2 Apple iPhone 1.0.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 Apple iPhone 1.1 Apple iPhone 1 Apple iPhone 0 |
| Not Vulnerable: |
Apple iPod Touch 3.1.1 Apple iPhone 3.1 |
Discussion
Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
Apple iPhone and iPod touch are prone to a security-bypass vulnerability.
Successfully exploiting these issues may allow attackers to bypass security restrictions, which may aid in further attacks.
This issue was previously covered in BID 36326 (Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities) but has been given its own record to better document it.
This issue affects the following:
iPhone OS 1.0 through 3.0.1
iPhone OS for iPod touch 1.1 through 3.0
Apple iPhone and iPod touch are prone to a security-bypass vulnerability.
Successfully exploiting these issues may allow attackers to bypass security restrictions, which may aid in further attacks.
This issue was previously covered in BID 36326 (Apple iPhone prior to 3.1 and iPod touch Prior to 3.1.1 Multiple Vulnerabilities) but has been given its own record to better document it.
This issue affects the following:
iPhone OS 1.0 through 3.0.1
iPhone OS for iPod touch 1.1 through 3.0
Exploit / POC
Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
To exploit this issue, an attacker requires physical access to an affected device.
To exploit this issue, an attacker requires physical access to an affected device.
Solution / Fix
Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
Apple iPhone and iPod touch Exchange Support Component Security Bypass Vulnerability
References:
References:
- iPhone Product Page (Apple)
- iPod touch Product Page (Apple)