Skip to main content

Apple iOS Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 4 Aug 2010 5257 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Apple iOS for iPhone, iPad and iPod, which could be exploited by remote attackers to take complete control of a vulnerable device.

1. Caused by a memory corruption error when processing Compact Font Format (CFF) data within a PDF document, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page using Mobile Safari.

2. Caused by an error in the kernel, which could allow attackers to gain elevated privileges and bypass sandbox restrictions.

Note: These flaws are currently being exploited by jailbreakme to remotely jailbreak Apple devices.


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Apple iPhone OS (iOS) versions 4.x
  • Apple iPhone OS (iOS) versions 3.x
  • Apple iPod OS (iOS) versions 4.x
  • Apple iPod OS (iOS) versions 3.x
  • Apple iPad OS (iOS) versions 3.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link