Apple iPhone Safari 'tel:' URI Handling Remote Denial of Service Vulnerability
BID:36386
Info
Apple iPhone Safari 'tel:' URI Handling Remote Denial of Service Vulnerability
| Bugtraq ID: | 36386 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2009 12:00AM |
| Updated: | Sep 15 2009 04:11PM |
| Credit: | cloud |
| Vulnerable: |
Apple iPhone 3.0.1 |
| Not Vulnerable: | |
Discussion
Apple iPhone Safari 'tel:' URI Handling Remote Denial of Service Vulnerability
The Safari browser on the Apple iPhone is prone to a denial-of-service vulnerability.
Successfully exploiting this issue may allow attackers to crash the application.
This issue affects Apple iPhone 3.0.1; other versions may be vulnerable as well.
The Safari browser on the Apple iPhone is prone to a denial-of-service vulnerability.
Successfully exploiting this issue may allow attackers to crash the application.
This issue affects Apple iPhone 3.0.1; other versions may be vulnerable as well.
Exploit / POC
Apple iPhone Safari 'tel:' URI Handling Remote Denial of Service Vulnerability
Attackers exploit this issue by enticing a victim to visit a malicious site. An exploit is available:
Attackers exploit this issue by enticing a victim to visit a malicious site. An exploit is available:
Solution / Fix
Apple iPhone Safari 'tel:' URI Handling Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple iPhone Safari 'tel:' URI Handling Remote Denial of Service Vulnerability
References:
References:
- iPhone Product Page (Apple)