PT-2009-4655 · Apple · Coreaudio+3
Tobias Klein
·
Published
2009-09-10
·
Updated
2022-08-09
·
CVE-2009-2206
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple iPhone OS versions prior to 3.1
Apple iPhone OS versions prior to 3.1.1 for iPod touch
Description
The issue is related to multiple heap-based buffer overflows in the AudioCodecs library within the CoreAudio component. This can be exploited by remote attackers through crafted AAC or MP3 files, such as a ringtone with malformed entries in the sample size table, leading to the execution of arbitrary code or a denial of service, which results in an application crash.
Recommendations
For Apple iPhone OS versions prior to 3.1, update to version 3.1 or later.
For Apple iPhone OS versions prior to 3.1.1 for iPod touch, update to version 3.1.1 or later.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiocodecs
Coreaudio
Ios
Ipod Touch