Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
BID:52364
Info
Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
| Bugtraq ID: | 52364 |
| Class: | Unknown |
| CVE: |
CVE-2012-0641 CVE-2012-0642 CVE-2012-0643 CVE-2012-0644 CVE-2012-0645 CVE-2012-0646 CVE-2012-0585 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 08 2012 12:00AM |
| Updated: | Sep 20 2012 05:10PM |
| Credit: | Erling Ellingsen of Facebook, pod2g, 2012 iOS Jailbreak Dream Team, Roland Kohler of the German Federal Ministry of Economics and Technology, Eric Melville of American Express |
| Vulnerable: |
Apple Safari 5.0.6 Apple Safari 4.1.2 for Windows Apple Safari 4.0.5 for Windows Apple Safari 4.0.5 Apple Safari 4.0.4 for Windows Apple Safari 4.0.4 Apple Safari 4.0.3 for Windows Apple Safari 4.0.3 Apple Safari 4.0.2 for Windows Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 3.2.3 for Windows Apple Safari 3.2.3 Apple Safari 5.1.1 for Windows Apple Safari 5.1.1 Apple Safari 5.1 for Windows Apple Safari 5.1 Apple Safari 5.0.6 for windows Apple Safari 5.0.5 for Windows Apple Safari 5.0.5 Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple Safari 4.1.3 for Windows Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Beta Apple Safari 4.0 Apple Safari 4 for Windows Apple Safari 4 Beta Apple Safari 4 Apple Mac Os X Server 10.7.3 Apple Mac Os X Server 10.7.2 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X 10.7.4 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 Apple iPod Touch 0 Apple iPhone 4.0.1 Apple iPhone 3.2.1 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 4.3.3 Apple iPhone 4.3.2 Apple iPhone 4.3.1 Apple iPhone 4.3.0 Apple iPhone 4.2.8 Apple iPhone 4.2.5 Apple iPhone 4.2.1 Apple iPhone 4.1 Apple iPhone 4.0.2 Apple iPhone 4.0.1 - Ipodtouch Apple iPhone 4.0.1 - Iphone Apple iPhone 4.0 - Ipodtouch Apple iPhone 4.0 - Iphone Apple iPhone 4.0 Apple iPhone 3.2.2 Apple iPhone 3.2 - Ipodtouch Apple iPhone 3.2 - Iphone Apple iPhone 3.2 Apple iPhone 3.1.3 - Ipodtouch Apple iPhone 3.1.3 - Iphone Apple iPhone 3.1.2 - Ipodtouch Apple iPhone 3.1.2 - Iphone Apple iPhone 3.1 - Ipodtouch Apple iPhone 3.1 - Iphone Apple iPhone 3.1 Apple iPhone 3.0.1 - Ipodtouch Apple iPhone 3.0.1 - Iphone Apple iPhone 3.0 - Ipodtouch Apple iPhone 3.0 - Iphone Apple iPhone 0 Apple iPad 3.2.1 Apple iPad 3.2.2 Apple iPad 3.2 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 |
| Not Vulnerable: |
Apple Safari 5.1.4 for Windows Apple Safari 5.1.4 Apple Mac Os X Server 10.7.4 Apple Mac Os X 10.7.4 Apple iOS 5.1 |
Discussion
Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
Apple iOS for iPhone, iPod touch, and iPad is prone to multiple security vulnerabilities. These issues affect the following components:
CFNetwork
HFS
Kernel
Passcode Lock
Safari
Siri
VPN
Successfully exploiting these issues may allow attackers to crash the affected device, bypass security restrictions, obtain sensitive information, or execute arbitrary code. Other attacks are also possible.
Apple iOS for iPhone, iPod touch, and iPad is prone to multiple security vulnerabilities. These issues affect the following components:
CFNetwork
HFS
Kernel
Passcode Lock
Safari
Siri
VPN
Successfully exploiting these issues may allow attackers to crash the affected device, bypass security restrictions, obtain sensitive information, or execute arbitrary code. Other attacks are also possible.
Exploit / POC
Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
Some of these issues may not require specific exploit code and may be trivial to exploit.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Apple Safari 5.1.1
Apple Safari 5.1.1 for Windows
Apple Mac Os X 10.7.2
Apple Mac Os X Server 10.7.1
Apple Mac Os X Server 10.7.2
Apple Mac Os X 10.7.3
Apple Safari 5.1
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Apple Safari 5.1.1
-
Apple Safari5.1.4LionManual.dmg
Safari for OS X Lion v10.7.3
http://www.apple.com/safari/download/ -
Apple Safari5.1.4SnowLeopardManual.dmg
Safari for Mac OS X v10.6.8
http://www.apple.com/safari/download/
Apple Safari 5.1.1 for Windows
-
Apple APPLE-SA-2012-03-12-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2012-03-12-1-SafariSetup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/
Apple Mac Os X 10.7.2
-
Apple MacOSXUpdCombo10.7.4.dmg
For OS X Lion v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Apple Mac Os X Server 10.7.1
-
Apple MacOSXServerUpdCombo10.7.4.dmg
For OS X Lion Server v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Apple Mac Os X Server 10.7.2
-
Apple MacOSXServerUpdCombo10.7.4.dmg
For OS X Lion Server v10.7 and v10.7.2
http://www.apple.com/support/downloads/
Apple Mac Os X 10.7.3
-
Apple MacOSXUpd10.7.4.dmg
For OS X Lion v10.7.3
http://www.apple.com/support/downloads/
Apple Safari 5.1
-
Apple Safari5.1.4LionManual.dmg
Safari for OS X Lion v10.7.3
http://www.apple.com/safari/download/ -
Apple Safari5.1.4SnowLeopardManual.dmg
Safari for Mac OS X v10.6.8
http://www.apple.com/safari/download/
References
Apple iPhone/iPad/iPod touch Prior to iOS 5.1 Multiple Vulnerabilities
References:
References:
- iOS Homepage (Apple)
- iPad Homepage (Apple)
- iPhone Product Page (Apple)
- iPod touch Product Page (Apple)