CERT-In Advisory
CIAD-2010-0060
Multiple Vulnerabilities in Apple iOS for iPhone, iPad and iPod
Original Issue Date: August 20, 2010
Severity Rating: High
Systems Affected
- Apple iOS for iPad 3.x
- Apple iPhone OS (iOS) 4.x
- Apple iPhone OS (iOS) for iPod touch 4.x
Overview
Multiple vulnerabilities have been reported in Apple iOS for iPhone, iPad and iPod, which could allow a remote attacker to execute an arbitrary code, bypass certain security restrictions and gain elevated privileges or potentially compromise a vulnerable system.
Description
1. CFF Font Parsing stack-based buffer overflow vulnerabilities
(
CVE-2010-1797
CVE-2010-2972
)
This vulnerability is caused due to a memory corruption error when processing Compact Font Format (CFF) data within a PDF document in Apple iOS on the iPhone, iPod touch and iPad. A remote attacker could exploit this vulnerability via a specially crafted CFF opcodes in embedded fonts in a PDF document to trigger a stack-based buffer overflow error. Successful exploitation of this vulnerability could allow a remoter attacker to execute an arbitrary code.
2. Privilege Escalation Vulnerability
(
CVE-2010-2973
)
This vulnerability is caused due to an integer overflow error in the kernel when handling IOSurface properties in Apple iOS on the iPhone, iPod touch and iPad. A remote attacker could exploit this vulnerability via unknown vectors to bypass sandbox restrictions and gain elevated privileges.
Solution
Apple iPhone and iPod touch: Upgrade to iOS version 4.0.2 using iTunes Apple iPad: Upgrade to iOS version 3.2.2 using iTunes
http://support.apple.com/kb/ht1414 20
Vendor Information
Apple
http://support.apple.com/kb/HT4291
http://support.apple.com/kb/HT4292
References
Secunia
http://secunia.com/advisories/40807/
SecurityFocus
http://www.securityfocus.com/bid/42151
US-CERT
http://www.kb.cert.org/vuls/id/275247
ISS X-Force
http://xforce.iss.net/xforce/xfdb/60856
VUPEN
http://www.vupen.com/english/advisories/2010/1992
CVE Name
CVE-2010-1797
CVE-2010-2973
CVE-2010-2972
CWE Name
CWE-264
CWE-119
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|