PT-2010-2889 · Apple · Ios+1

Nishant Das Patnaik

·

Publicado

2010-03-29

·

Atualizado

2010-03-30

·

CVE-2010-1179

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari on Apple iPhone OS version 3.1.3 for iPod touch
Description The issue allows remote attackers to cause a denial of service, potentially leading to an application crash, or possibly execute arbitrary code. This is achieved by including a large integer in the numcolors attribute of a recolorinfo element in a VML file.
Recommendations For Safari on Apple iPhone OS version 3.1.3 for iPod touch, consider avoiding the use of VML files with large integers in the numcolors attribute of a recolorinfo element until a fix is available. As a temporary workaround, restrict access to potentially malicious VML files to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1179

Produtos afetados

Safari
Ios