Apple iOS Calendar Cross Site Scripting Vulnerability
BID:50161
Info
Apple iOS Calendar Cross Site Scripting Vulnerability
| Bugtraq ID: | 50161 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3254 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2011 12:00AM |
| Updated: | Oct 12 2011 12:00AM |
| Credit: | Rick Deacon |
| Vulnerable: |
Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 |
| Not Vulnerable: |
Apple iOS 5 |
Discussion
Apple iOS Calendar Cross Site Scripting Vulnerability
Apple iOS is prone to a cross-site scripting vulnerability that affects the calendar.
An attacker may leverage this issue to execute arbitrary script code in the local domain. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following Apple systems are vulnerable:
iOS 4.2.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 4.2.0 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 4.2.0 through 4.3.5 for iPad
NOTE: This issue was previously discussed in BID 50086 (Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities) but has been given its own record to better document it.
Apple iOS is prone to a cross-site scripting vulnerability that affects the calendar.
An attacker may leverage this issue to execute arbitrary script code in the local domain. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
The following Apple systems are vulnerable:
iOS 4.2.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 4.2.0 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 4.2.0 through 4.3.5 for iPad
NOTE: This issue was previously discussed in BID 50086 (Apple iPhone/iPad/iPod touch Prior to iOS 5 Multiple Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Apple iOS Calendar Cross Site Scripting Vulnerability
Attackers can exploit this issue by tricking an unsuspecting victim into opening a malicious invitation note.
Attackers can exploit this issue by tricking an unsuspecting victim into opening a malicious invitation note.
Solution / Fix
Apple iOS Calendar Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.