PT-2010-2886 · Apple · Ios+1

Nishant Das Patnaik

·

Publicado

2010-03-29

·

Atualizado

2010-03-30

·

CVE-2010-1176

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari on Apple iPhone OS version 3.1.3
Description The issue allows remote attackers to cause a denial of service, potentially leading to an application crash, or possibly execute arbitrary code. This is achieved through various vectors, including an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods.
Recommendations For Safari on Apple iPhone OS version 3.1.3, consider updating to a newer version to mitigate the risk of exploitation, as no specific fix is provided for this version. As a temporary workaround, restrict access to potentially vulnerable web pages to minimize the risk of denial of service or code execution.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1176

Produtos afetados

Safari
Ios