PT-2010-2886 · Apple · Ios+1
Nishant Das Patnaik
·
Published
2010-03-29
·
Updated
2010-03-30
·
CVE-2010-1176
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Safari on Apple iPhone OS version 3.1.3
Description
The issue allows remote attackers to cause a denial of service, potentially leading to an application crash, or possibly execute arbitrary code. This is achieved through various vectors, including an array of long strings, an array of IMG elements with crafted strings in their
SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods.Recommendations
For Safari on Apple iPhone OS version 3.1.3, consider updating to a newer version to mitigate the risk of exploitation, as no specific fix is provided for this version. As a temporary workaround, restrict access to potentially vulnerable web pages to minimize the risk of denial of service or code execution.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safari
Ios