Home→Descriptions→SA48454
| Secunia ID | |
| CVE-ID | |
| Release Date |
20 Mar 2012 |
| Last Change |
09 May 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. Security BypassThis covers vulnerabilities or security issues where malicious users or people can bypass certain security mechanisms of the application. The actual impact varies significantly depending on the design and purpose of the affected application. SpoofingThis covers various vulnerabilities where it is possible for malicious users or people to impersonate other users or systems. |
| Description |
Multiple vulnerabilities have been reported in Apple iOS, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system. 1) An error within Safari when opening a new window using "window.open()" can be exploited to display arbitrary content while showing the URL of a trusted web site in the address bar. This vulnerability is confirmed in iOS version 5.1 (9B176) on iPhone 4 and 4th generation iPod touch. Other versions and devices may also be affected. 2) Some vulnerabilities are caused due to a bundled vulnerable version of WebKit. For more information: 3) An error within the WebKit component can be exploited to corrupt memory. Successful exploitation of vulnerabilities #2 and #3 may allow execution of arbitrary code. |
| Solution |
Apply iOS 5.1.1 Software Update. |
| Reported by |
1) David Vieira-Kurz, MajorSecurity. |
| Original Advisory |
MajorSecurity: |