First published: Fri Jun 19 2009(Updated: )
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | =1.0.0 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.0 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
iStyle @cosme iPhone OS | =1.1.3 | |
iStyle @cosme iPhone OS | =1.1.4 | |
iStyle @cosme iPhone OS | =1.1.5 | |
iStyle @cosme iPhone OS | =2.0 | |
iStyle @cosme iPhone OS | =2.0.0 | |
iStyle @cosme iPhone OS | =2.0.1 | |
iStyle @cosme iPhone OS | =2.0.2 | |
iStyle @cosme iPhone OS | =2.1 | |
iStyle @cosme iPhone OS | =2.1.1 | |
iStyle @cosme iPhone OS | =2.2 | |
iStyle @cosme iPhone OS | =2.2.1 | |
iStyle @cosme iPhone OS | ||
Apple iPod touch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0961 is classified as a high severity vulnerability, allowing potential remote exploitation.
To fix CVE-2009-0961, you should update your Apple iPhone OS or iPod touch to the latest version available.
CVE-2009-0961 affects Apple iPhone OS versions 1.0 through 2.2.1 and iPhone OS for iPod touch versions 1.1 through 2.2.1.
CVE-2009-0961 allows remote attackers to make calls without user approval by exploiting the vulnerability in the Mail component.
There are no known workarounds for CVE-2009-0961; updating to a secure version is the only recommended solution.