APPLE-SA-2008-11-13Vendor advisory
http://lists.apple.com/archives/security-announce//2008/Nov/msg00001.html CVE-2008-2303
Apple iPhone / Apple iPod Touch < 2.0 - Multiple Remote Vulnerabilities
Record summary
CVE-2008-2303 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApple iPhone / Apple iPod Touch < 2.0 - Multiple Remote VulnerabilitiesExploitDB exploitby Hiromitsu TakagiNot analyzed1 file
References
9APPLE-SA-2008-07-11Vendor advisory
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html 31074Third-party advisory
http://secunia.com/advisories/31074 32706Third-party advisory
http://secunia.com/advisories/32706 support.apple.comConfirmation
http://support.apple.com/kb/HT3298 30186vdb entry
http://www.securityfocus.com/bid/30186 ADV-2008-2094vdb entry
http://www.vupen.com/english/advisories/2008/2094/references ipod-iphone-javascript-code-execution(43736)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/43736 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2303