PT-2009-4655 · Apple · Coreaudio+3

Tobias Klein

·

Published

2009-09-10

·

Updated

2022-08-09

·

CVE-2009-2206

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple iPhone OS versions prior to 3.1 Apple iPhone OS versions prior to 3.1.1 for iPod touch
Description The issue is related to multiple heap-based buffer overflows in the AudioCodecs library within the CoreAudio component. This can be exploited by remote attackers through crafted AAC or MP3 files, such as a ringtone with malformed entries in the sample size table, leading to the execution of arbitrary code or a denial of service, which results in an application crash.
Recommendations For Apple iPhone OS versions prior to 3.1, update to version 3.1 or later. For Apple iPhone OS versions prior to 3.1.1 for iPod touch, update to version 3.1.1 or later.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2009-2206

Affected Products

Audiocodecs
Coreaudio
Ios
Ipod Touch