First published: Tue Nov 25 2008(Updated: )
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPod touch | ||
iStyle @cosme iPhone OS | ||
Apple Mobile Safari | ||
iStyle @cosme iPhone OS | =1.0 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
iStyle @cosme iPhone OS | =1.1.3 | |
iStyle @cosme iPhone OS | =1.1.4 | |
iStyle @cosme iPhone OS | =1.1.5 | |
iStyle @cosme iPhone OS | =2.0 | |
iStyle @cosme iPhone OS | =2.0.1 | |
iStyle @cosme iPhone OS | =2.0.2 | |
iStyle @cosme iPhone OS | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4232 is considered a high severity vulnerability as it allows attackers to spoof a user interface.
To fix CVE-2008-4232, users should update their Apple Safari browser to the latest version available.
CVE-2008-4232 affects Apple Safari on iPhone OS versions 2.0 to 2.1 and previous versions of iPhone OS.
CVE-2008-4232 allows for UI spoofing attacks through crafted HTML documents.
CVE-2008-4232 specifically affects Apple Safari and does not impact other web browsers.