PT-2009-5160 · Apple · Uikit+1

Abraham Vegh

·

Published

2009-09-10

·

Updated

2017-08-17

·

CVE-2009-2796

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iPhone OS versions 3.0 through 3.0.1 Apple iPhone OS version 3.0 for iPod touch
Description The issue allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password, specifically affecting the UIKit component.
Recommendations For Apple iPhone OS versions 3.0 through 3.0.1, consider using a secure method to enter passwords, avoiding the undo feature for password input. For Apple iPhone OS version 3.0 for iPod touch, use an alternative, secure password entry method to minimize the risk of password discovery.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2796

Affected Products

Uikit
Ios