PT-2008-5006 · Apple · Iphone+1

Bryce Cogswell

+1

·

Published

2008-09-10

·

Updated

2011-03-08

·

CVE-2008-3631

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iPod touch versions 2.0 through 2.0.2 Apple iPhone versions 2.0 through 2.0.2
Description The issue concerns the Application Sandbox, which fails to properly isolate third-party applications. This allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.
Recommendations For Apple iPod touch versions 2.0 through 2.0.2, consider restricting access to sensitive files within third-party applications until a fix is available. For Apple iPhone versions 2.0 through 2.0.2, consider implementing additional security measures to prevent unauthorized access to files within third-party applications' sandboxes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3631

Affected Products

Iphone
Ipod Touch