First published: Mon Jul 14 2008(Updated: )
Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone | =1.0 | |
Apple iPhone | =1.1.3 | |
Apple iPhone | =1.1.4 | |
Apple iPhone | =1.02 | |
Apple iPod touch | =1.1 | |
Apple iPod touch | =1.1.1 | |
Apple iPod touch | =1.1.2 | |
Apple iPod touch | =1.1.3 | |
Apple iPod touch | =1.1.4 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
Apple Mobile Safari |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2303 is classified as a high severity vulnerability due to its potential to allow remote code execution or crash applications.
To fix CVE-2008-2303, users should update their Safari browser to a version that has addressed this vulnerability.
CVE-2008-2303 affects Safari on Apple iPhone and iPod touch running versions prior to 2.0.
The impacts of CVE-2008-2303 can include arbitrary code execution and denial of service through application crashes.
CVE-2008-2303 was discovered by security researchers focusing on vulnerabilities in software applications.