PT-2009-5160 · Apple · Uikit+1
Abraham Vegh
·
Published
2009-09-10
·
Updated
2017-08-17
·
CVE-2009-2796
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iPhone OS versions 3.0 through 3.0.1
Apple iPhone OS version 3.0 for iPod touch
Description
The issue allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password, specifically affecting the UIKit component.
Recommendations
For Apple iPhone OS versions 3.0 through 3.0.1, consider using a secure method to enter passwords, avoiding the undo feature for password input.
For Apple iPhone OS version 3.0 for iPod touch, use an alternative, secure password entry method to minimize the risk of password discovery.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uikit
Ios