SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   OS (Other)  >   Apple iOS Vendors:   Apple
Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information
SecurityTracker Alert ID:  1026180
SecurityTracker URL:  http://securitytracker.com/id/1026180
CVE Reference:   CVE-2011-3245, CVE-2011-3246, CVE-2011-3253, CVE-2011-3254, CVE-2011-3255, CVE-2011-3256, CVE-2011-3257, CVE-2011-3259, CVE-2011-3260, CVE-2011-3261, CVE-2011-3426, CVE-2011-3427, CVE-2011-3429, CVE-2011-3430, CVE-2011-3431, CVE-2011-3432, CVE-2011-3434   (Links to External Site)
Date:  Oct 13 2011
Impact:   Denial of service via network, Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via local system, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 5.0
Description:   Multiple vulnerabilities were reported in Apple iOS. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions. A remote user can conduct cross-site scripting attacks. A local user can obtain potentially sensitive information.

The iPhone 3GS, iPhone 4, iPod touch (3rd generation and later), and iPad products are affected.

A local user can exploit a flaw in the keyboard to view the last character of a previously typed password [CVE-2011-3245]. Paul Mousdicas reported this vulnerability.

A remote user can create a specially crafted HTTP or HTTPS URL that, when loaded by the target user, will send cookies for the referenced domain to another domain [CVE-2011-3246]. Erling Ellingsen of Facebook reported this vulnerability.

CalDAV does not verify the SSL certificate. A remote user in a privileged network position may intercept user credentials sent between the target device and a CalDAV calendar server [CVE-2011-3253]. Leszek Tasiemski of nSense reported this vulnerability.

A remote user can create a specially crafted calendar invitation that, when loaded by the target user, will inject script in the local domain [CVE-2011-3254]. Versions prior to iOS 4.2.0 are not affected. Rick Deacon reported this vulnerability.

The system may log the user's AppleID password to a local file. A local user (application) may be able to access the credentials [CVE-2011-3255]. Peter Quade of qdevelop reported this vulnerability.

A remote user can create a specially crafted FreeType font that, when loaded by the target user, will execute arbitrary code on the target user's device [CVE-2011-3256]. The vendor reported this vulnerability.

When multiple mail exchange accounts are configured and connect to the same server, a session may be assigned a session cookie for a different account [CVE-2011-3257]. Bob Sielken of IBM reported this vulnerability.

A remote user with the ability to connect to a listening service on the target device can establish an incomplete TCP connection to consume excessive memory and cause the device to reset [CVE-2011-3259]. Wouter van der Veer of Topicus I&I and Josh Enders reported this vulnerability.

A remote user can create a specially crafted Word file that, when loaded by the target user, will trigger a buffer overflow and execute arbitrary code on the target device [CVE-2011-3260]. Tobias Klein (via Verisign iDefense Labs) reported this vulnerability.

A remote user can create a specially crafted Excel file that, when loaded by the target user, will trigger a double free memory error and execute arbitrary code on the target device [CVE-2011-3261]. Tobias Klein of www.trapkit.de reported this vulnerability.

A remote user can create a specially crafted file on a web site that, when loaded by the target user, will run arbitrary scripting code in the context of that site [CVE-2011-3426]. Christian Matthies (via iDefense VCP) and Yoshinori Oota from Business Architects Inc (via with JP/CERT) reported this vulnerability.

The system accepts certificates signed using MD5 and may expose X.509 protocols to spoofing, man in the middle attacks, and information disclosure [CVE-2011-3427].

A physically local user can access the parental restrictions password [CVE-2011-3429]. An anonymous researcher reported this vulnerability.

Some configuration settings applied via configuration profiles did not function properly uder non-English languages. As a result, settings may be improperly displayed [CVE-2011-3430]. Florian Kreitmaier of Siemens CERT reported this vulnerability.

A local user can switch betwee applications using the four-finger swipe gesture to cause the display to reveal the previous application state [CVE-2011-3431]. Abe White of Hedonic Software Inc. reported this vulnerability.

A remote user can create a specially crafted 'tel:' URI that, when loaded by the target user, will cause the target user's device to hang [CVE-2011-3432]. Simon Young of Anglia Ruskin University reported this vulnerability.

The system may log WiFi credentials to a local file. A local user (application) may be able to access the credentials [CVE-2011-3434]. Laurent OUDOT of TEHTRI Security reported this vulnerability.

Impact:   A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can cause denial of service conditions.

A local user can obtain potentially sensitive information.

A remote user can access the target user's cookies (including authentication cookies), if any, associated with a target site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

Solution:   The vendor has issued a fix (5).

The vendor's advisory is available at:

http://support.apple.com/kb/HT4999

Vendor URL:  support.apple.com/kb/HT4999 (Links to External Site)
Cause:   Access control error, Boundary error, Input validation error, Resource error

Message History:   This archive entry has one or more follow-up message(s) listed below.
Feb 3 2012 (Red Hat Issues Fix for FreeType) Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information
Red Hat has issued a fix for FreeType for Red Hat Enterprise Linux 5.6.
Mar 15 2013 (Oracle Issues Fix for FreeType) Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information
Oracle has issued a fix for FreeType for Solaris 8, 9, 10, and 11.1



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2016, SecurityGlobal.net LLC