Help - Search - Members - Calendar
Full Version: Apple Iphone / Ipod Touch Multiple Vulnerabilities
TotalChoice Hosting Family Forums > TotalChoice Hosting General Support > Security Discussions > Software/Scripts/Other Alerts
TCH-Thomas
From: Secunia
secunia.com/advisories/28497/

Rating: Highly critical

Description:
Two vulnerabilities and a security issue have been reported in Apple iPhone and iPod touch, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or to compromise a vulnerable device.

1) An unspecified error in the handling of URLs exists in Safari. This can be exploited to cause a memory corruption when a user is enticed to access a specially crafted URL.

Successful exploitation may allow execution of arbitrary code.

2) An error in the handling of emergency calls can be exploited to bypass the Passcode Lock feature and allows users with physical access to an iPhone to launch applications without the passcode.

This security issue is reported in iPhone v1.0 through v1.1.2 only.

3) An error in Safari can be exploited by malicious people to conduct cross-site scripting attacks.

Solution:
Update to version 1.1.3 (downloadable and installable via iTunes).
TCH-Bruce
Thanks Thomas
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.