SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   FreeType Vendors:   freetype.org
(Oracle Issues Fix for FreeType) Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information
SecurityTracker Alert ID:  1028299
SecurityTracker URL:  http://securitytracker.com/id/1028299
CVE Reference:   CVE-2011-3256   (Links to External Site)
Date:  Mar 15 2013
Impact:   Denial of service via network, Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via local system, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   Multiple vulnerabilities were reported in Apple iOS. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions. A remote user can conduct cross-site scripting attacks. A local user can obtain potentially sensitive information. FreeType is affected by one vulnerability.

The iPhone 3GS, iPhone 4, iPod touch (3rd generation and later), and iPad products are affected.

A local user can exploit a flaw in the keyboard to view the last character of a previously typed password [CVE-2011-3245]. Paul Mousdicas reported this vulnerability.

A remote user can create a specially crafted HTTP or HTTPS URL that, when loaded by the target user, will send cookies for the referenced domain to another domain [CVE-2011-3246]. Erling Ellingsen of Facebook reported this vulnerability.

CalDAV does not verify the SSL certificate. A remote user in a privileged network position may intercept user credentials sent between the target device and a CalDAV calendar server [CVE-2011-3253]. Leszek Tasiemski of nSense reported this vulnerability.

A remote user can create a specially crafted calendar invitation that, when loaded by the target user, will inject script in the local domain [CVE-2011-3254]. Versions prior to iOS 4.2.0 are not affected. Rick Deacon reported this vulnerability.

The system may log the user's AppleID password to a local file. A local user (application) may be able to access the credentials [CVE-2011-3255]. Peter Quade of qdevelop reported this vulnerability.

A remote user can create a specially crafted FreeType font that, when loaded by the target user, will execute arbitrary code on the target user's device [CVE-2011-3256]. The vendor reported this vulnerability.

When multiple mail exchange accounts are configured and connect to the same server, a session may be assigned a session cookie for a different account [CVE-2011-3257]. Bob Sielken of IBM reported this vulnerability.

A remote user with the ability to connect to a listening service on the target device can establish an incomplete TCP connection to consume excessive memory and cause the device to reset [CVE-2011-3259]. Wouter van der Veer of Topicus I&I and Josh Enders reported this vulnerability.

A remote user can create a specially crafted Word file that, when loaded by the target user, will trigger a buffer overflow and execute arbitrary code on the target device [CVE-2011-3260]. Tobias Klein (via Verisign iDefense Labs) reported this vulnerability.

A remote user can create a specially crafted Excel file that, when loaded by the target user, will trigger a double free memory error and execute arbitrary code on the target device [CVE-2011-3261]. Tobias Klein of www.trapkit.de reported this vulnerability.

A remote user can create a specially crafted file on a web site that, when loaded by the target user, will run arbitrary scripting code in the context of that site [CVE-2011-3426]. Christian Matthies (via iDefense VCP) and Yoshinori Oota from Business Architects Inc (via with JP/CERT) reported this vulnerability.

The system accepts certificates signed using MD5 and may expose X.509 protocols to spoofing, man in the middle attacks, and information disclosure [CVE-2011-3427].

A physically local user can access the parental restrictions password [CVE-2011-3429]. An anonymous researcher reported this vulnerability.

Some configuration settings applied via configuration profiles did not function properly uder non-English languages. As a result, settings may be improperly displayed [CVE-2011-3430]. Florian Kreitmaier of Siemens CERT reported this vulnerability.

A local user can switch betwee applications using the four-finger swipe gesture to cause the display to reveal the previous application state [CVE-2011-3431]. Abe White of Hedonic Software Inc. reported this vulnerability.

A remote user can create a specially crafted 'tel:' URI that, when loaded by the target user, will cause the target user's device to hang [CVE-2011-3432]. Simon Young of Anglia Ruskin University reported this vulnerability.

The system may log WiFi credentials to a local file. A local user (application) may be able to access the credentials [CVE-2011-3434]. Laurent OUDOT of TEHTRI Security reported this vulnerability.

Impact:   A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can cause denial of service conditions.

A local user can obtain potentially sensitive information.

A remote user can access the target user's cookies (including authentication cookies), if any, associated with a target site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.

Solution:   Oracle has issued a fix for CVE-2011-3256 for Solaris.

The Oracle advisory is available at:

https://blogs.oracle.com/sunsecurity/entry/cve_2011_3256_denial_of

Cause:   Access control error, Boundary error, Input validation error, Resource error
Underlying OS:  UNIX (Solaris - SunOS)
Underlying OS Comments:  8, 9, 10, 11.1

Message History:   This archive entry is a follow-up to the message listed below.
Oct 13 2011 Apple iOS Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Scripting Attacks, and Deny Service and Let Local Users Obtain Information



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC