MAAS History
Archives
« iPhone Application Security > FreeBit ServersMan 3.1.5 DOS Crash Attack | Main | iPad Black Hat Search Optimization »
Wednesday
Feb032010

APPLE-SA-2010-02-02-1 iPhone OS 3.1.3/iPhone OS 3.1.3/iPodtouch

Apple released a security update for the iPhone OS/iPod Touch which users should install that addresses various security issues. There was a buffer overflow in the handling of mp4 audio files and a buffer underflow in ImageIO handling of tiff files which could lead to application termination or code execution. These issues are addressed by using improved bound checking. 

WebKit had been updated to address input validation when handling FTP directory listings. It is possible that a maliciously design FTP can be used to cause a DOS or disclose information. Also in WebKit HTML Media Element failures in WebKit can result in Mail loading remote media even if remote image loading is disabled. A maliciously crafted file can be used for Reconnaissance related to user activity. The memory curruption bypass issues have allso been fixed.

There is also an iTunes update that should be installed as well. This includes various performance improvements. 

PrintView Printer Friendly Version

EmailEmail Article to Friend

References (1)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.
Member Account Required
You must have a member account on this website in order to post comments. Log in to your account to enable posting.