PT-2010-2886 · Apple · Ios+1

Nishant Das Patnaik

·

Published

2010-03-29

·

Updated

2010-03-30

·

CVE-2010-1176

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari on Apple iPhone OS version 3.1.3
Description The issue allows remote attackers to cause a denial of service, potentially leading to an application crash, or possibly execute arbitrary code. This is achieved through various vectors, including an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods.
Recommendations For Safari on Apple iPhone OS version 3.1.3, consider updating to a newer version to mitigate the risk of exploitation, as no specific fix is provided for this version. As a temporary workaround, restrict access to potentially vulnerable web pages to minimize the risk of denial of service or code execution.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1176

Affected Products

Safari
Ios