PT-2008-5006 · Apple · Iphone+1
Bryce Cogswell
+1
·
Published
2008-09-10
·
Updated
2011-03-08
·
CVE-2008-3631
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iPod touch versions 2.0 through 2.0.2
Apple iPhone versions 2.0 through 2.0.2
Description
The issue concerns the Application Sandbox, which fails to properly isolate third-party applications. This allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.
Recommendations
For Apple iPod touch versions 2.0 through 2.0.2, consider restricting access to sensitive files within third-party applications until a fix is available.
For Apple iPhone versions 2.0 through 2.0.2, consider implementing additional security measures to prevent unauthorized access to files within third-party applications' sandboxes.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iphone
Ipod Touch