CVE-2008-1588: Input Validation
Published Jul 14, 2008
·Updated
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.
Affected Software
14 affected components
Apple iPhone=1.0
Apple iPhone=1.1.3
Apple iPhone=1.1.4
Apple iPhone=1.02
Apple iPod touch=1.1
Apple iPod touch=1.1.1
Apple iPod touch=1.1.2
Apple iPod touch=1.1.3
Apple iPod touch=1.1.4
iPhone OS=1.0.1
iPhone OS=1.0.2
iPhone OS=1.1.1
iPhone OS=1.1.2
Safari
Event History
Jul 14, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:41 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-1588?
CVE-2008-1588 is considered a moderate severity vulnerability.
2
How do I fix CVE-2008-1588?
To mitigate CVE-2008-1588, users should update to the latest version of Safari available for their devices.
3
What devices are affected by CVE-2008-1588?
CVE-2008-1588 affects Safari on Apple iPhone and iPod touch running versions prior to 2.0.
4
What kind of attack does CVE-2008-1588 facilitate?
CVE-2008-1588 allows remote attackers to spoof the address bar using Unicode ideographic spaces in the URL.
5
Can CVE-2008-1588 impact user security?
Yes, CVE-2008-1588 can jeopardize user security by facilitating phishing attacks through URL spoofing.