On TechRepublic: 2 humane ways to fire someone
BNET Business Network:
BNET
TechRepublic
ZDNet

September 27th, 2007

Apple patches 10 iPhone security holes

Posted by Ryan Naraine @ 11:42 am

Categories: Apple, Botnets, Browsers, Data theft, Digital rights management, Exploit code, Google, Hackers, Open source, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Apple iPhone, Apple Safari, Phone, Vulnerability, Apple Inc., Web Browser, E-mail, Bluetooth, Telecom & Utilities, Security

Apple patches 10 iPhone security holesApple has shipped an iPhone software update to patch 10 different vulnerabilities that could allow malicious hackers to launch executable code, steal e-mail credentials or take control of the device’s phone-dialing capabilities.

The mega-patch, which shipped today as iPhone v1.1.1, patches seven holes in Safari, a code execution and denial-of-service bug in Bluetooth, and two flaws affecting the built-in Mail service.

The skinny, via Apple’s advisory:

Bluetooth (CVE-2007-3753) — An input validation issue in the iPhone’s Bluetooth server could allow the use of maliciously-crafted Service Discovery Protocol (SDP) packets to trigger an unexpected application termination or arbitrary code execution.

Mail (CVE-2007-3754 and CVE-2007-3755) — When Mail is configured to use SSL for incoming and outgoing connections, it does not warn the user when the identity of the mail server has changed or cannot be trusted. An attacker capable of intercepting the connection may be able to impersonate the user’s mail server and obtain the user’s email credentials or other sensitive information. Separately, following a telephone (”tel:”) link in Mail will dial a phone number without confirmation.

The seven Mobile Safari vulnerabilities — which likely affect the desktop (Windows and Mac) versions of the browser — range from disclosure of URL contents, dialing phone numbers with a confirmation dialog, cross-site scripting and the manipulation of the contents of documents served over HTTPS.

Michal Zalewski, the browser hacking guru recently hired by Google, is credited with reporting three of the Safari vulnerabilities.

In addition to the iPhone patches, Apple is expected to ship a monster Mac OS X update later today. This will include fixes for the year-old QuickTime code execution issue that made headlines recently.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 25 Talkback(s)
You are right about the conspiracy
You are so right... It's a consipiracy... Apple consipred with the rest of the world to expose the dumbest people around us.

Only someone so dumb they could barely breathe would be dumb enough... (Read the rest)
Posted by: i8thecat Posted on: 10/03/07 You are currently: a Guest | | Terms of Use
I wonder if they patched anything else.... happy  BitTwiddler | 09/27/07
RE: Apple patches 10 iPhone security holes  spamsucker@... | 09/27/07
Apple did this on purpose  NonZealot | 09/27/07
Lay-off the crack son .  Intellihence | 09/27/07
He could be right  voska | 09/27/07
vulnerable to what? any examples? NT  Non-Zealand | 09/27/07
Did you read Ryan's article?  Badgered | 09/27/07
I was thinking the exact same thing  voska | 09/27/07
hahahahahahaha  Non-Zealand | 09/27/07
re: timing  Badgered | 09/27/07
Sorry to tell you....  eldernorm | 09/28/07
Your analogy is WWWAAAAAAYYYY off  laura.b | 10/01/07
You are right about the conspiracy  i8thecat | 10/03/07
lots of other apple updates...  Arm A. Geddon | 09/27/07
I didn't see where ....  ShadeTree | 09/27/07
Apple didn't brick any phones  frgough | 09/28/07
So how many unlocked iphones got bricked?  kraterz | 09/27/07
Lawsuits?  Eriamjh | 09/28/07
Get a clue doom caller  i8thecat | 10/03/07
RE: Apple patches 10 iPhone security holes  Kobashrer | 09/27/07
I wish somebody would patch the whiner's mouths  YinToYourYang-22527499 | 09/27/07
Is it not their job?  laura.b | 09/28/07
Pathetic...  jasonp@... | 09/28/07
Pathetic..  monroe.johnson@... | 09/28/07
wow  Protector | 09/28/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here