Apple iOS Mail Cookie Synchronization Validation Information Disclosure Vulnerability
BID:50156
Info
Apple iOS Mail Cookie Synchronization Validation Information Disclosure Vulnerability
| Bugtraq ID: | 50156 |
| Class: | Unknown |
| CVE: |
CVE-2011-3257 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 12 2011 12:00AM |
| Updated: | Oct 12 2011 12:00AM |
| Credit: | Bob Sielken of IBM |
| Vulnerable: |
Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 |
| Not Vulnerable: |
Apple iOS 5 |
Discussion
Apple iOS Mail Cookie Synchronization Validation Information Disclosure Vulnerability
Apple iOS is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information due to an incorrect mail cookie synchronization. This may allow the attacker to obtain credentials or other sensitive information. Information harvested may aid in further attacks.
The following Apple systems are vulnerable:
iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later
iOS 3.2 through 4.3.5 for iPad
NOTE: This issue was previously discussed in BID 50086 (Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities) but has been given its own record to better document it
Apple iOS is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information due to an incorrect mail cookie synchronization. This may allow the attacker to obtain credentials or other sensitive information. Information harvested may aid in further attacks.
The following Apple systems are vulnerable:
iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later
iOS 3.2 through 4.3.5 for iPad
NOTE: This issue was previously discussed in BID 50086 (Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities) but has been given its own record to better document it
Exploit / POC
Apple iOS Mail Cookie Synchronization Validation Information Disclosure Vulnerability
Attackers require local access to an affected device to exploit.
Attackers require local access to an affected device to exploit.
Solution / Fix
Apple iOS Mail Cookie Synchronization Validation Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apple iOS Mail Cookie Synchronization Validation Information Disclosure Vulnerability
References:
References:
- Apple iOS Homepage (Apple)