First published: Wed Sep 10 2008(Updated: )
Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-party application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPod touch | =2.0.1 | |
Apple iPod touch | =2.0.2 | |
Apple iPod touch | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3631 is considered a medium severity vulnerability due to its potential to expose sensitive data from third-party applications.
To fix CVE-2008-3631, users should update their Apple iPod touch or iPhone to version 2.0.3 or later, which addresses the issue.
CVE-2008-3631 is a sandboxing vulnerability that allows cross-application access to files within a third-party application's sandbox.
CVE-2008-3631 affects Apple iPod touch models running versions 2.0 through 2.0.2 and iPhone models also running versions 2.0 through 2.0.2.
Attackers exploiting CVE-2008-3631 can read arbitrary files from a third-party application's sandbox, compromising sensitive user data.