APPLE-SA-2009-06-17-1Vendor advisory
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html CVE-2009-0961
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (1)
Record summary
CVE-2009-0961 has a selected CVSS score of 5.0; EIP currently links 3 catalogued exploits.
Description
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBApple iPhone 2.2.1 - Call Approval Dialog Security Bypass (1)ExploitDB exploitby Collin MullinerNot analyzed1 file
ExploitDBApple iPhone 2.2.1 - Call Approval Dialog Security Bypass (2)ExploitDB exploitby Collin MullinerNot analyzed1 file
ExploitDBApple iPhone 2.2.1 - Call Approval Dialog Security Bypass (3)ExploitDB exploitby Collin MullinerNot analyzed1 file
References
755238vdb entry
http://osvdb.org/55238 support.apple.comConfirmation
http://support.apple.com/kb/HT3639 35414vdb entry
http://www.securityfocus.com/bid/35414 ADV-2009-1621vdb entry
http://www.vupen.com/english/advisories/2009/1621 iphone-ipod-mail-security-bypass(51210)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/51210 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-0961