PT-2010-2889 · Apple · Ios+1

Nishant Das Patnaik

·

Published

2010-03-29

·

Updated

2010-03-30

·

CVE-2010-1179

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari on Apple iPhone OS version 3.1.3 for iPod touch
Description The issue allows remote attackers to cause a denial of service, potentially leading to an application crash, or possibly execute arbitrary code. This is achieved by including a large integer in the numcolors attribute of a recolorinfo element in a VML file.
Recommendations For Safari on Apple iPhone OS version 3.1.3 for iPod touch, consider avoiding the use of VML files with large integers in the numcolors attribute of a recolorinfo element until a fix is available. As a temporary workaround, restrict access to potentially malicious VML files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1179

Affected Products

Safari
Ios