CVE-2008-4232: Medium severity apple ipod touch vulnerability
Published Nov 25, 2008
·Updated
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
Affected Software
16 affected components
Apple iPod touch
iPhone OS
Safari
iPhone OS=1.0
iPhone OS=1.0.1
iPhone OS=1.0.2
iPhone OS=1.1
iPhone OS=1.1.1
iPhone OS=1.1.2
iPhone OS=1.1.3
iPhone OS=1.1.4
iPhone OS=1.1.5
iPhone OS=2.0
iPhone OS=2.0.1
iPhone OS=2.0.2
iPhone OS=2.1
Event History
Nov 25, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-4232?
CVE-2008-4232 is considered a high severity vulnerability as it allows attackers to spoof a user interface.
2
How do I fix CVE-2008-4232?
To fix CVE-2008-4232, users should update their Apple Safari browser to the latest version available.
3
Which products are affected by CVE-2008-4232?
CVE-2008-4232 affects Apple Safari on iPhone OS versions 2.0 to 2.1 and previous versions of iPhone OS.
4
What type of attack is possible with CVE-2008-4232?
CVE-2008-4232 allows for UI spoofing attacks through crafted HTML documents.
5
Can CVE-2008-4232 affect other browsers?
CVE-2008-4232 specifically affects Apple Safari and does not impact other web browsers.