CVE-2009-0961: Medium severity iphone os vulnerability
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0961?
CVE-2009-0961 is classified as a high severity vulnerability, allowing potential remote exploitation.
How do I fix CVE-2009-0961?
To fix CVE-2009-0961, you should update your Apple iPhone OS or iPod touch to the latest version available.
What versions are affected by CVE-2009-0961?
CVE-2009-0961 affects Apple iPhone OS versions 1.0 through 2.2.1 and iPhone OS for iPod touch versions 1.1 through 2.2.1.
What kind of attack does CVE-2009-0961 allow?
CVE-2009-0961 allows remote attackers to make calls without user approval by exploiting the vulnerability in the Mail component.
Is there a workaround for CVE-2009-0961?
There are no known workarounds for CVE-2009-0961; updating to a secure version is the only recommended solution.