PT-2008-5006 · Apple · Iphone+1
Bryce Cogswell
+1
·
Publicado
2008-09-10
·
Atualizado
2011-03-08
·
CVE-2008-3631
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iPod touch versions 2.0 through 2.0.2
Apple iPhone versions 2.0 through 2.0.2
Description
The issue concerns the Application Sandbox, which fails to properly isolate third-party applications. This allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.
Recommendations
For Apple iPod touch versions 2.0 through 2.0.2, consider restricting access to sensitive files within third-party applications until a fix is available.
For Apple iPhone versions 2.0 through 2.0.2, consider implementing additional security measures to prevent unauthorized access to files within third-party applications' sandboxes.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Iphone
Ipod Touch