CVE-2007-3755: Input Validation
Published Sep 27, 2007
·Updated
Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.
Affected Software
3 affected components
apple iPhone OS=1.0.2
apple iPhone=1.0
apple iPhone OS=1.0.1
Remediation
Event History
Sep 27, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2007-3755?
CVE-2007-3755 is a vulnerability in Mail on Apple iPhone 1.1.1 that allows attackers to force calls to arbitrary telephone numbers without user consent.
2
What versions are affected by CVE-2007-3755?
CVE-2007-3755 affects Apple iPhone OS versions 1.0, 1.0.1, and 1.0.2.
3
How can I mitigate CVE-2007-3755?
To mitigate CVE-2007-3755, it is recommended to upgrade to a patched version of the iPhone OS.
4
What kind of attacks can exploit CVE-2007-3755?
CVE-2007-3755 can be exploited through user-assisted attacks using malicious 'tel:' links.
5
What is the impact of CVE-2007-3755?
The impact of CVE-2007-3755 is that users may unintentionally make calls to unwanted or fraudulent numbers.