Apple iOS Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple iOS for iPhone, iPad and iPod, which could be exploited by remote attackers to take complete control of a vulnerable device.
1. Caused by a memory corruption error when processing Compact Font Format (CFF) data within a PDF document, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page using Mobile Safari.
2. Caused by an error in the kernel, which could allow attackers to gain elevated privileges and bypass sandbox restrictions.
Note: These flaws are currently being exploited by jailbreakme to remotely jailbreak Apple devices.
Impact
- Elevation of Privilege
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Apple iPhone OS (iOS) versions 4.x
- Apple iPhone OS (iOS) versions 3.x
- Apple iPod OS (iOS) versions 4.x
- Apple iPod OS (iOS) versions 3.x
- Apple iPad OS (iOS) versions 3.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apple iPhone and iPod touch - Upgrade to iOS version 4.0.2 using iTunes:
http://support.apple.com/kb/ht1414 - Apple iPad - Upgrade to iOS version 3.2.2 using iTunes:
http://support.apple.com/kb/ht1414
Vulnerability Identifier
Source
Related Link
Share with