Apple iPhone/iPod touch Prior to iOS 4 Passcode Lock Authentication Bypass Vulnerability
BID:41067
Info
Apple iPhone/iPod touch Prior to iOS 4 Passcode Lock Authentication Bypass Vulnerability
| Bugtraq ID: | 41067 |
| Class: | Design Error |
| CVE: |
CVE-2010-1754 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 21 2010 12:00AM |
| Updated: | Jun 23 2010 03:08PM |
| Credit: | Sidney San Martin of DeepTech, Inc |
| Vulnerable: |
Apple iPod Touch 3.1.3 Apple iPod Touch 3.1.2 Apple iPod Touch 3.1.1 Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPod Touch 0 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 3.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 Apple iPhone 0 |
| Not Vulnerable: |
Apple iOS 4 |
Discussion
Apple iPhone/iPod touch Prior to iOS 4 Passcode Lock Authentication Bypass Vulnerability
Apple iOS for iPhone and iPod touch is prone to an authentication-bypass vulnerability.
An attacker with physical access to a locked device can exploit this issue to bypass the passcode and access the user's data. This may aid in further attacks.
Versions prior to iOS 4 are vulnerable.
NOTE: This issue was previously covered in BID 41016 (Apple iPhone/iPod touch Prior to iOS 4 Multiple Vulnerabilities) but has been given its own record to better document it.
Apple iOS for iPhone and iPod touch is prone to an authentication-bypass vulnerability.
An attacker with physical access to a locked device can exploit this issue to bypass the passcode and access the user's data. This may aid in further attacks.
Versions prior to iOS 4 are vulnerable.
NOTE: This issue was previously covered in BID 41016 (Apple iPhone/iPod touch Prior to iOS 4 Multiple Vulnerabilities) but has been given its own record to better document it.
Solution / Fix
Apple iPhone/iPod touch Prior to iOS 4 Passcode Lock Authentication Bypass Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.