SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   OS (Other)  >   Apple iOS Vendors:   Apple Computer
Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information
SecurityTracker Alert ID:  1026180
SecurityTracker URL:  http://securitytracker.com/id/1026180
CVE Reference:   CVE-2011-3245, CVE-2011-3246, CVE-2011-3253, CVE-2011-3254, CVE-2011-3255, CVE-2011-3256, CVE-2011-3257, CVE-2011-3259, CVE-2011-3260, CVE-2011-3261, CVE-2011-3426, CVE-2011-3427, CVE-2011-3429, CVE-2011-3430, CVE-2011-3431, CVE-2011-3432, CVE-2011-3434   (Links to External Site)
Date:  Oct 13 2011
Impact:   Denial of service via network, Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via local system, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 5.0
Description:   Multiple vulnerabilities were reported in Apple iOS. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions. A remote user can conduct cross-site scripting attacks. A local user can obtain potentially sensitive information.

The iPhone 3GS, iPhone 4, iPod touch (3rd generation and later), and iPad products are affected.

A local user can exploit a flaw in the keyboard to view the last character of a previously typed password [CVE-2011-3245]. Paul Mousdicas reported this vulnerability.

A remote user can create a specially crafted HTTP or HTTPS URL that, when loaded by the target user, will send cookies for the referenced domain to another domain [CVE-2011-3246]. Erling Ellingsen of Facebook reported this vulnerability.

CalDAV does not verify the SSL certificate. A remote user in a privileged network position may intercept user credentials sent between the target device and a CalDAV calendar server [CVE-2011-3253]. Leszek Tasiemski of nSense reported this vulnerability.

A remote user can create a specially crafted calendar invitation that, when loaded by the target user, will inject script in the local domain [CVE-2011-3254]. Versions prior to iOS 4.2.0 are not affected. Rick Deacon reported this vulnerability.

The system may log the user's AppleID password to a local file. A local user (application) may be able to access the credentials [CVE-2011-3255]. Peter Quade of qdevelop reported this vulnerability.

A remote user can create a specially crafted FreeType font that, when loaded by the target user, will execute arbitrary code on the target user's device [CVE-2011-3256]. The vendor reported this vulnerability.

When multiple mail exchange accounts are configured and connect to the same server, a session may be assigned a session cookie for a different account [CVE-2011-3257]. Bob Sielken of IBM reported this vulnerability.

A remote user with the ability to connect to a listening service on the target device can establish an incomplete TCP connection to consume excessive memory and cause the device to reset [CVE-2011-3259]. Wouter van der Veer of Topicus I&I and Josh Enders reported this vulnerability.

A remote user can create a specially crafted Word file that, when loaded by the target user, will trigger a buffer overflow and execute arbitrary code on the target device [CVE-2011-3260]. Tobias Klein (via Verisign iDefense Labs) reported this vulnerability.

A remote user can create a specially crafted Excel file that, when loaded by the target user, will trigger a double free memory error and execute arbitrary code on the target device [CVE-2011-3261]. Tobias Klein of www.trapkit.de reported this vulnerability.

A remote user can create a specially crafted file on a web site that, when loaded by the target user, will run arbitrary scripting code in the context of that site [CVE-2011-3426]. Christian Matthies (via iDefense VCP) and Yoshinori Oota from Business Architects Inc (via with JP/CERT) reported this vulnerability.

The system accepts certificates signed using MD5 and may expose X.509 protocols to spoofing, man in the middle attacks, and information disclosure [CVE-2011-3427].

A physically local user can access the parental restrictions password [CVE-2011-3429]. An anonymous researcher reported this vulnerability.

Some configuration settings applied via configuration profiles did not function properly uder non-English languages. As a result, settings may be improperly displayed [CVE-2011-3430]. Florian Kreitmaier of Siemens CERT reported this vulnerability.

A local user can switch betwee applications using the four-finger swipe gesture to cause the display to reveal the previous application state [CVE-2011-3431]. Abe White of Hedonic Software Inc. reported this vulnerability.

A remote user can create a specially crafted 'tel:' URI that, when loaded by the target user, will cause the target user's device to hang [CVE-2011-3432]. Simon Young of Anglia Ruskin University reported this vulnerability.

The system may log WiFi credentials to a local file. A local user (application) may be able to access the credentials [CVE-2011-3434]. Laurent OUDOT of TEHTRI Security reported this vulnerability.

Impact:   A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can cause denial of service conditions.

A local user can obtain potentially sensitive information.

A remote user can access the target user's cookies (including authentication cookies), if any, associated with a target site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

Solution:   The vendor has issued a fix (5).

The vendor's advisory is available at:

http://support.apple.com/kb/HT4999

Vendor URL:  support.apple.com/kb/HT4999 (Links to External Site)
Cause:   Access control error, Boundary error, Input validation error, Resource error
Underlying OS:  

Message History:   This archive entry has one or more follow-up message(s) listed below.
Feb 3 2012 (Red Hat Issues Fix for FreeType) Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information   (bugzilla@redhat.com)
Red Hat has issued a fix for FreeType for Red Hat Enterprise Linux 5.6.
Mar 15 2013 (Oracle Issues Fix for FreeType) Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information
Oracle has issued a fix for FreeType for Solaris 8, 9, 10, and 11.1



 Source Message Contents

Date:  Thu, 13 Oct 2011 02:23:05 +0000
Subject:  Apple iOS


APPLE-SA-2011-10-12-1 iOS 5 Software Update

Keyboards
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  A user may be able to determine information about the last
character of a password
Description:  The keyboard used to type the last character of a
password was briefly displayed the next time the keyboard was used.
CVE-ID
CVE-2011-3245 : Paul Mousdicas

CFNetwork
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Visiting a maliciously crafted website may lead to the
disclosure of sensitive information
Description:  An issue existed in CFNetwork's handling of HTTP
cookies. When accessing a maliciously crafted HTTP or HTTPS URL,
CFNetwork could incorrectly send the cookies for a domain to a server
outside that domain.
CVE-ID
CVE-2011-3246 : Erling Ellingsen of Facebook

CalDAV
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  An attacker with a privileged network position may intercept
user credentials or other sensitive information from a CalDAV
calendar server
Description:  CalDAV did not check that the SSL certificate presented
by the server was trusted.
CVE-ID
CVE-2011-3253 : Leszek Tasiemski of nSense

Calendar
Available for:  iOS 4.2.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 4.2.0 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 4.2.0 through 4.3.5 for iPad
Impact:  Viewing a maliciously crafted calendar invitation may inject
script in the local domain
Description:  A script injection issue existed in Calendar's handling
of invitation notes. This issue is addressed through improved
escaping of special characters in invitation notes. This issues does
not affect devices prior to iOS 4.2.0.
CVE-ID
CVE-2011-3254 : Rick Deacon

CFNetwork
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  User's AppleID password may be logged to a local file
Description:  A user's AppleID password and username were logged to a
file that was readable by applications on the system. This is
resolved by no longer logging these credentials.
CVE-ID
CVE-2011-3255 : Peter Quade of qdevelop

CoreGraphics
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Viewing a document containing a maliciously crafted font may
lead to arbitrary code execution
Description:  Multiple memory corruption existed in freetype, the
most serious of which may lead to arbitrary code execution when
processing a maliciously crafted font.
CVE-ID
CVE-2011-3256 : Apple

Data Access
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  An exchange mail cookie management issue could incorrectly
cause data synchronization across different accounts
Description:  When multiple mail exchange accounts are configured
which connect to the same server, a session could potentially receive
a valid cookie corresponding to a different account. This issue is
addressed by ensuring that cookies are separated across different
accounts.
CVE-ID
CVE-2011-3257 : Bob Sielken of IBM

Kernel
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  A remote attacker may cause a device reset
Description:  The kernel failed to promptly reclaim memory from
incomplete TCP connections. An attacker with the ability to connect
to a listening service on an iOS device could exhaust system
resources.
CVE-ID
CVE-2011-3259 : Wouter van der Veer of Topicus I&I, and Josh Enders

OfficeImport
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Viewing a maliciously crafted Word file may lead to an
unexpected application termination or arbitrary code execution
Description:  A buffer overflow existed in OfficeImport's handling of
Microsoft Word documents.
CVE-ID
CVE-2011-3260 : Tobias Klein working with Verisign iDefense Labs

OfficeImport
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Viewing a maliciously crafted Excel file may lead to an
unexpected application termination or arbitrary code execution
Description:  A double free issue existed in OfficeImport's handling
of Excel files.
CVE-ID
CVE-2011-3261 : Tobias Klein of www.trapkit.de

Safari
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Opening maliciously crafted files on certain websites may
lead to a cross-site scripting attack
Description:  iOS did not support the 'attachment' value for the HTTP
Content-Disposition header. This header is used by many websites to
serve files that were uploaded to the site by a third-party, such as
attachments in web-based e-mail applications. Any script in files
served with this header value would run as if the file had been
served inline, with full access to other resources on the origin
server. This issue is addressed by loading attachments in an isolated
security origin with no access to resources on other sites.
CVE-ID
CVE-2011-3426 : Christian Matthies working with iDefense VCP,
Yoshinori Oota from Business Architects Inc working with JP/CERT

Data Security
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Support for X.509 certificates with MD5 hashes may expose
users to spoofing and information disclosure as attacks improve
Description:  Certificates signed using the MD5 hash algorithm were
accepted by iOS. This algorithm has known cryptographic weaknesses.
Further research or a misconfigured certificate authority could have
allowed the creation of X.509 certificates with attacker controlled
values that would have been trusted by the system. This would have
exposed X.509 based protocols to spoofing, man in the middle attacks,
and information disclosure. This update disables support for an X.509
certificate with an MD5 hash for any use other than as a trusted root
certificate.
CVE-ID
CVE-2011-3427

Settings
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  An attacker with physical access to a device may be able to
recover the restrictions passcode
Description:  The parental restrictions functionality enforces UI
restrictions. Configuring parental restrictions is protected by a
passcode, which was previously stored in plaintext on disk. This
issue is addressed by securely storing the parental restrictions
passcode in the system keychain.
CVE-ID
CVE-2011-3429 : an anonymous reporter

Settings
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Misleading UI
Description:  Configurations and settings applied via configuration
profiles did not appear to function properly under any non-English
language. Settings could be improperly displayed as a result. This
issue is addressed by fixing a localization error.
CVE-ID
CVE-2011-3430 : Florian Kreitmaier of Siemens CERT

Home screen
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Switching between applications may lead to the disclosure of
sensitive application information
Description:  When switching between applications with the four-
finger app switching gesture, the display could have revealed the
previous application state. This issue is addressed by ensuring that
the system properly calls the applicationWillResignActive: method
when transitioning between applications.
CVE-ID
CVE-2011-3431 : Abe White of Hedonic Software Inc.

UIKit Alerts
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  Visiting a malicious website may cause an unexpected device
hang
Description:  An excessive maximum text layout length permitted
malicious websites to cause iOS to hang when drawing acceptance
dialogs for very long tel: URIs. This issue is addressed by using a
more reasonable maximum URI size.
CVE-ID
CVE-2011-3432 : Simon Young of Anglia Ruskin University

WiFi
Available for:  iOS 3.0 through 4.3.5 for iPhone 3GS and iPhone 4,
iOS 3.1 through 4.3.5 for iPod touch (3rd generation) and later,
iOS 3.2 through 4.3.5 for iPad
Impact:  WiFi credentials may be logged to a local file
Description:  WiFi credentials including the passphrase and
encryption keys were logged to a file that was readable by
applications on the system. This is resolved by no longer logging
these credentials.
CVE-ID
CVE-2011-3434 : Laurent OUDOT of TEHTRI Security


 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2014, SecurityGlobal.net LLC