Secunia SmallBusiness
Overview
Advisories
Research
Forums
Create Profile
Our Commitment
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Secunia Advisory SA50586

Apple iOS Multiple Vulnerabilities
Secunia Advisory SA50586
Secunia VIM 4.0 - Free Trial
Release Date 2012-09-20
   
Popularity 5,610 views
Comments 0 comments

Criticality level Highly criticalHighly critical
Impact Security Bypass
Cross Site Scripting
Spoofing
Exposure of system information
Exposure of sensitive information
Privilege escalation
System access
Where From remote
Authentication level This information is available to Secunia VIM customers
   
Report reliability This information is available to Secunia VIM customers
Solution Status Unpatched
   
Systems affected This information is available to Secunia VIM customers
Approve distribution This information is available to Secunia VIM customers
Remediation status Secunia VIM
   
Operating System
Apple iOS 5.x for iPhone 3GS and later
Apple iOS for iPad 5.x
Apple iOS for iPod touch 5.x

Secunia CVSS Score This information is available to Secunia VIM Customers
CVE Reference(s) CVE-2011-1167 CVSS score available to Secunia VIM customers
CVE-2011-1944 CVSS score available to Secunia VIM customers
CVE-2011-2821 CVSS score available to Secunia VIM customers
CVE-2011-2834 CVSS score available to Secunia VIM customers
CVE-2011-2845 CVSS score available to Secunia VIM customers
CVE-2011-3016 CVSS score available to Secunia VIM customers
CVE-2011-3021 CVSS score available to Secunia VIM customers
CVE-2011-3026 CVSS score available to Secunia VIM customers
CVE-2011-3027 CVSS score available to Secunia VIM customers
CVE-2011-3032 CVSS score available to Secunia VIM customers
CVE-2011-3034 CVSS score available to Secunia VIM customers
CVE-2011-3035 CVSS score available to Secunia VIM customers
CVE-2011-3036 CVSS score available to Secunia VIM customers
CVE-2011-3037 CVSS score available to Secunia VIM customers
CVE-2011-3038 CVSS score available to Secunia VIM customers
CVE-2011-3039 CVSS score available to Secunia VIM customers
CVE-2011-3040 CVSS score available to Secunia VIM customers
CVE-2011-3041 CVSS score available to Secunia VIM customers
CVE-2011-3042 CVSS score available to Secunia VIM customers
CVE-2011-3043 CVSS score available to Secunia VIM customers
CVE-2011-3044 CVSS score available to Secunia VIM customers
CVE-2011-3048 CVSS score available to Secunia VIM customers
CVE-2011-3050 CVSS score available to Secunia VIM customers
CVE-2011-3053 CVSS score available to Secunia VIM customers
CVE-2011-3059 CVSS score available to Secunia VIM customers
CVE-2011-3060 CVSS score available to Secunia VIM customers
CVE-2011-3064 CVSS score available to Secunia VIM customers
CVE-2011-3067 CVSS score available to Secunia VIM customers
CVE-2011-3068 CVSS score available to Secunia VIM customers
CVE-2011-3069 CVSS score available to Secunia VIM customers
CVE-2011-3071 CVSS score available to Secunia VIM customers
CVE-2011-3073 CVSS score available to Secunia VIM customers
CVE-2011-3074 CVSS score available to Secunia VIM customers
CVE-2011-3075 CVSS score available to Secunia VIM customers
CVE-2011-3076 CVSS score available to Secunia VIM customers
CVE-2011-3078 CVSS score available to Secunia VIM customers
CVE-2011-3081 CVSS score available to Secunia VIM customers
CVE-2011-3086 CVSS score available to Secunia VIM customers
CVE-2011-3089 CVSS score available to Secunia VIM customers
CVE-2011-3090 CVSS score available to Secunia VIM customers
CVE-2011-3105 CVSS score available to Secunia VIM customers
CVE-2011-3328 CVSS score available to Secunia VIM customers
CVE-2011-3457 CVSS score available to Secunia VIM customers
CVE-2011-3913 CVSS score available to Secunia VIM customers
CVE-2011-3919 CVSS score available to Secunia VIM customers
CVE-2011-3924 CVSS score available to Secunia VIM customers
CVE-2011-3926 CVSS score available to Secunia VIM customers
CVE-2011-3958 CVSS score available to Secunia VIM customers
CVE-2011-3966 CVSS score available to Secunia VIM customers
CVE-2011-3968 CVSS score available to Secunia VIM customers
CVE-2011-3969 CVSS score available to Secunia VIM customers
CVE-2011-3971 CVSS score available to Secunia VIM customers
CVE-2011-4599 CVSS score available to Secunia VIM customers
CVE-2012-0680 CVSS score available to Secunia VIM customers
CVE-2012-0682 CVSS score available to Secunia VIM customers
CVE-2012-0683 CVSS score available to Secunia VIM customers
CVE-2012-1126 CVSS score available to Secunia VIM customers
CVE-2012-1127 CVSS score available to Secunia VIM customers
CVE-2012-1128 CVSS score available to Secunia VIM customers
CVE-2012-1129 CVSS score available to Secunia VIM customers
CVE-2012-1130 CVSS score available to Secunia VIM customers
CVE-2012-1131 CVSS score available to Secunia VIM customers
CVE-2012-1132 CVSS score available to Secunia VIM customers
CVE-2012-1133 CVSS score available to Secunia VIM customers
CVE-2012-1134 CVSS score available to Secunia VIM customers
CVE-2012-1135 CVSS score available to Secunia VIM customers
CVE-2012-1136 CVSS score available to Secunia VIM customers
CVE-2012-1137 CVSS score available to Secunia VIM customers
CVE-2012-1138 CVSS score available to Secunia VIM customers
CVE-2012-1139 CVSS score available to Secunia VIM customers
CVE-2012-1140 CVSS score available to Secunia VIM customers
CVE-2012-1141 CVSS score available to Secunia VIM customers
CVE-2012-1142 CVSS score available to Secunia VIM customers
CVE-2012-1143 CVSS score available to Secunia VIM customers
CVE-2012-1144 CVSS score available to Secunia VIM customers
CVE-2012-1173 CVSS score available to Secunia VIM customers
CVE-2012-1520 CVSS score available to Secunia VIM customers
CVE-2012-1521 CVSS score available to Secunia VIM customers
CVE-2012-2815 CVSS score available to Secunia VIM customers
CVE-2012-2818 CVSS score available to Secunia VIM customers
CVE-2012-3589 CVSS score available to Secunia VIM customers
CVE-2012-3590 CVSS score available to Secunia VIM customers
CVE-2012-3591 CVSS score available to Secunia VIM customers
CVE-2012-3592 CVSS score available to Secunia VIM customers
CVE-2012-3593 CVSS score available to Secunia VIM customers
CVE-2012-3594 CVSS score available to Secunia VIM customers
CVE-2012-3595 CVSS score available to Secunia VIM customers
CVE-2012-3596 CVSS score available to Secunia VIM customers
CVE-2012-3597 CVSS score available to Secunia VIM customers
CVE-2012-3598 CVSS score available to Secunia VIM customers
CVE-2012-3599 CVSS score available to Secunia VIM customers
CVE-2012-3600 CVSS score available to Secunia VIM customers
CVE-2012-3601 CVSS score available to Secunia VIM customers
CVE-2012-3602 CVSS score available to Secunia VIM customers
CVE-2012-3603 CVSS score available to Secunia VIM customers
CVE-2012-3604 CVSS score available to Secunia VIM customers
CVE-2012-3605 CVSS score available to Secunia VIM customers
CVE-2012-3608 CVSS score available to Secunia VIM customers
CVE-2012-3609 CVSS score available to Secunia VIM customers
CVE-2012-3610 CVSS score available to Secunia VIM customers
CVE-2012-3611 CVSS score available to Secunia VIM customers
CVE-2012-3612 CVSS score available to Secunia VIM customers
CVE-2012-3613 CVSS score available to Secunia VIM customers
CVE-2012-3614 CVSS score available to Secunia VIM customers
CVE-2012-3615 CVSS score available to Secunia VIM customers
CVE-2012-3617 CVSS score available to Secunia VIM customers
CVE-2012-3618 CVSS score available to Secunia VIM customers
CVE-2012-3620 CVSS score available to Secunia VIM customers
CVE-2012-3624 CVSS score available to Secunia VIM customers
CVE-2012-3625 CVSS score available to Secunia VIM customers
CVE-2012-3626 CVSS score available to Secunia VIM customers
CVE-2012-3627 CVSS score available to Secunia VIM customers
CVE-2012-3628 CVSS score available to Secunia VIM customers
CVE-2012-3629 CVSS score available to Secunia VIM customers
CVE-2012-3630 CVSS score available to Secunia VIM customers
CVE-2012-3631 CVSS score available to Secunia VIM customers
CVE-2012-3633 CVSS score available to Secunia VIM customers
CVE-2012-3634 CVSS score available to Secunia VIM customers
CVE-2012-3635 CVSS score available to Secunia VIM customers
CVE-2012-3636 CVSS score available to Secunia VIM customers
CVE-2012-3637 CVSS score available to Secunia VIM customers
CVE-2012-3638 CVSS score available to Secunia VIM customers
CVE-2012-3639 CVSS score available to Secunia VIM customers
CVE-2012-3640 CVSS score available to Secunia VIM customers
CVE-2012-3641 CVSS score available to Secunia VIM customers
CVE-2012-3642 CVSS score available to Secunia VIM customers
CVE-2012-3644 CVSS score available to Secunia VIM customers
CVE-2012-3645 CVSS score available to Secunia VIM customers
CVE-2012-3646 CVSS score available to Secunia VIM customers
CVE-2012-3647 CVSS score available to Secunia VIM customers
CVE-2012-3648 CVSS score available to Secunia VIM customers
CVE-2012-3650 CVSS score available to Secunia VIM customers
CVE-2012-3651 CVSS score available to Secunia VIM customers
CVE-2012-3652 CVSS score available to Secunia VIM customers
CVE-2012-3653 CVSS score available to Secunia VIM customers
CVE-2012-3655 CVSS score available to Secunia VIM customers
CVE-2012-3656 CVSS score available to Secunia VIM customers
CVE-2012-3658 CVSS score available to Secunia VIM customers
CVE-2012-3659 CVSS score available to Secunia VIM customers
CVE-2012-3660 CVSS score available to Secunia VIM customers
CVE-2012-3661 CVSS score available to Secunia VIM customers
CVE-2012-3663 CVSS score available to Secunia VIM customers
CVE-2012-3664 CVSS score available to Secunia VIM customers
CVE-2012-3665 CVSS score available to Secunia VIM customers
CVE-2012-3666 CVSS score available to Secunia VIM customers
CVE-2012-3667 CVSS score available to Secunia VIM customers
CVE-2012-3668 CVSS score available to Secunia VIM customers
CVE-2012-3669 CVSS score available to Secunia VIM customers
CVE-2012-3670 CVSS score available to Secunia VIM customers
CVE-2012-3671 CVSS score available to Secunia VIM customers
CVE-2012-3672 CVSS score available to Secunia VIM customers
CVE-2012-3673 CVSS score available to Secunia VIM customers
CVE-2012-3674 CVSS score available to Secunia VIM customers
CVE-2012-3676 CVSS score available to Secunia VIM customers
CVE-2012-3677 CVSS score available to Secunia VIM customers
CVE-2012-3678 CVSS score available to Secunia VIM customers
CVE-2012-3679 CVSS score available to Secunia VIM customers
CVE-2012-3680 CVSS score available to Secunia VIM customers
CVE-2012-3681 CVSS score available to Secunia VIM customers
CVE-2012-3682 CVSS score available to Secunia VIM customers
CVE-2012-3683 CVSS score available to Secunia VIM customers
CVE-2012-3684 CVSS score available to Secunia VIM customers
CVE-2012-3686 CVSS score available to Secunia VIM customers
CVE-2012-3691 CVSS score available to Secunia VIM customers
CVE-2012-3693 CVSS score available to Secunia VIM customers
CVE-2012-3695 CVSS score available to Secunia VIM customers
CVE-2012-3696 CVSS score available to Secunia VIM customers
CVE-2012-3703 CVSS score available to Secunia VIM customers
CVE-2012-3704 CVSS score available to Secunia VIM customers
CVE-2012-3706 CVSS score available to Secunia VIM customers
CVE-2012-3708 CVSS score available to Secunia VIM customers
CVE-2012-3710 CVSS score available to Secunia VIM customers
CVE-2012-3722 CVSS score available to Secunia VIM customers
CVE-2012-3724 CVSS score available to Secunia VIM customers
CVE-2012-3725 CVSS score available to Secunia VIM customers
CVE-2012-3726 CVSS score available to Secunia VIM customers
CVE-2012-3727 CVSS score available to Secunia VIM customers
CVE-2012-3728 CVSS score available to Secunia VIM customers
CVE-2012-3729 CVSS score available to Secunia VIM customers
CVE-2012-3730 CVSS score available to Secunia VIM customers
CVE-2012-3731 CVSS score available to Secunia VIM customers
CVE-2012-3732 CVSS score available to Secunia VIM customers
CVE-2012-3733 CVSS score available to Secunia VIM customers
CVE-2012-3734 CVSS score available to Secunia VIM customers
CVE-2012-3735 CVSS score available to Secunia VIM customers
CVE-2012-3736 CVSS score available to Secunia VIM customers
CVE-2012-3737 CVSS score available to Secunia VIM customers
CVE-2012-3738 CVSS score available to Secunia VIM customers
CVE-2012-3739 CVSS score available to Secunia VIM customers
CVE-2012-3740 CVSS score available to Secunia VIM customers
CVE-2012-3741 CVSS score available to Secunia VIM customers
CVE-2012-3742 CVSS score available to Secunia VIM customers
CVE-2012-3743 CVSS score available to Secunia VIM customers
CVE-2012-3744 CVSS score available to Secunia VIM customers
CVE-2012-3745 CVSS score available to Secunia VIM customers
CVE-2012-3746 CVSS score available to Secunia VIM customers
CVE-2012-3747 CVSS score available to Secunia VIM customers
  

Description

Multiple vulnerabilities have been reported in Apple iOS, which can be exploited by malicious, local users to disclose system information and gain escalated privileges, by malicious people to disclose potentially sensitive information, conducts spoofing attacks, and compromise a user's device, and by malicious people with physical access to disclose potentially sensitive information and bypass certain security restrictions.

1) An error in CFNetwork when handling certain URLs can be exploited to submit data to an incorrect hostname.

2) Some vulnerabilities exist in the bundled version of FreeType.

For more information:
SA48268

3) An error in CoreMedia when processing Sorenson encoded movies can be exploited to dereference uninitialized memory.

4) An error in DHCP when connection to WiFi networks may disclose a MAC address of previously accessed networks via DNAv4 protocol.

5) ImageIO bundles a vulnerable version of LibTIFF library.

For more information:
SA43593
SA48684

6) ImageIO bundles a vulnerable version of libpng library.

For more information:
SA46148
SA48026
SA48587

7) An double-free error exists in ImageIO when processing JPEG images.

8) An error in International Components for Unicode when handling locale IDs can be exploited to cause a stack-based buffer overflow.

9) A boundary error in IPSec when loading racoon configuration files can be exploited to cause a buffer overflow.

10) An error in the kernel when handling packet filter IOCTLs can be exploited to dereference an invalid pointer.

11) An error in the kernel when related to BPF interpreter can be exploited to disclose certain memory content.

12) Some vulnerabilities exist in the bundled version of libxml library.

For more information:
SA44711
SA46632

13) An error in Mail when handling attachments can be exploited to disclose a unintended attachments via the "Content-ID" field.

14) An error in Mail within Data Protection on attachments can be exploited to access an attachment without a passcode.

15) An error in Mail when processing S/MIME signed messages does not display the correct identity of a signer and can be exploited to spoof an identity via the "From" field.

16) An error in Messages when multiple email addresses are used may result in replies being sent using the wrong address.

17) An error in Office Viewer when processing document files may result in data being stored in temporary files in a decrypted state even when data protection / encryption is enabled.

18) An error in OpenGL when performing GLSL compilation can be exploited to corrupt memory.

19) An error in Passcode Lock related to "Slide to Power Off" slider may disclose the last used third party application.

20) An error in Passcode Lock related to termination of FaceTime calls may allow bypassing the screen lock.

21) An error in Passcode Lock related to lock screen photos may disclose all photos accessible at the lock screen.

22) An error in Passcode Lock related to Emergency Dialer screen may allow making FaceTime calls and disclose user's contacts.

23) An error in Passcode Lock related to the camera usage may allow bypassing the screen lock.

24) An error in Passcode Lock related lock state management may allow bypassing the screen lock.

25) An error in Restrictions during purchase transactions may result in transaction being made without the Appled ID credentials.

26) An error in Safari when handling certain Unicode characters may allow spoofing the lock icon in the page title.

27) An error in Safari when handling password input elements with a disabled "autocomplete" attribute allowed the input to be autocompleted.

28) An error in System Logs due to weak restrictions on the "/var/log" directory can be exploited by sandboxed applications to disclose log details.

29) An error in Telephony did not properly display the return address of SMS messages.

30) An off-by-one error in Telephony when handling SMS data headers can be exploited to disable cellular activity.

31) An error in UIKit within UIWebView may result in unencrypted files being stored even when a passcode is enabled.

32) Multiple vulnerabilities exist in WebKit.

For more information:
SA46594
SA47231
SA47694
SA47938
SA48016
SA48265
SA48274
SA48512
SA48618
SA48732
SA48992
SA49194
SA49277
SA49724
SA49906
SA50058


Solution
Upgrade to iOS 6 via Software Update.

Provided and/or discovered by
8, 28) Reported by the vendor.

The vendor also credits:
1) Erling Ellingsen, Facebook
3) Will Dormann, CERT/CC
4) Mark Wuergler, Immunity, Inc.
7) Phil, PKJE Consulting
9, 10) iOS Jailbreak Dream Team
11) Dan Rosenberg
13) Angelo Prado, salesforce.com Product Security Team
14) Stephen Prairie, Travelers Insurance, Erich Stuntebeck of AirWatch
15) Anonymous person
16) Rodney S. Foley, Gnomesoft, LLC
17) Salvatore Cataudella, Open Systems Technologies
19) Chris Lawrence, DBB
20, 24) Ian Vitek, 2Secure AB
21, 22) Ade Barkah, BlueWax Inc.
23) Sebastian Spanninger, Austrian Federal Computing Centre (BRZ)
25) Kevin Makens, Redwood High School
26) Boku Kihara, Lepidum
27) Dan Poltawski, Moodle
29, 30) pod2g
31) Ben Smith, Box

Original Advisory
Apple:
http://support.apple.com/kb/HT5503

Other references
Further details available to Secunia VIM customers

Deep Links
Links available to Secunia VIM customers


Do you have additional information related to this advisory?

Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com

Subject: Apple iOS Multiple Vulnerabilities
 
No posts yet

-

You must be logged in to post a comment.




 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2013 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability