First published: Wed Jun 10 2009(Updated: )
Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =3.0.4b | |
Apple Mobile Safari | =2.0.3-417.9.3 | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =3.0.1-beta | |
Apple Mobile Safari | =2.0.1 | |
Apple Mobile Safari | =2.0.3 | |
Apple Mobile Safari | =2.0.2 | |
Apple Mobile Safari | =3.0.0 | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | <=3.2.2 | |
Apple Mobile Safari | =3.0.3b | |
Apple Mobile Safari | =3.1.1 | |
Apple Mobile Safari | =2.0.3-417.9 | |
Apple Mobile Safari | =2.0.3-417.9.2 | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =2.0 | |
Apple Mobile Safari | =2.0.3-417.8 | |
Apple Mobile Safari | =3.1.2 | |
Apple Mobile Safari | =3.1.0b | |
Apple Mobile Safari | =3.1.0 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =3.0.0b | |
Apple Mobile Safari | =2.0.0 | |
Apple Mobile Safari | =3.2.0 | |
Apple Mobile Safari | =3.0.2b | |
Apple Mobile Safari | =3.0.1b | |
Apple Mobile Safari | =3.2.1 | |
Apple Mobile Safari | =3.0 | |
iStyle @cosme iPhone OS | =1.0.0 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.0 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
iStyle @cosme iPhone OS | =1.1.3 | |
iStyle @cosme iPhone OS | =1.1.4 | |
iStyle @cosme iPhone OS | =1.1.5 | |
iStyle @cosme iPhone OS | =2.0 | |
iStyle @cosme iPhone OS | =2.0.0 | |
iStyle @cosme iPhone OS | =2.0.1 | |
iStyle @cosme iPhone OS | =2.0.2 | |
iStyle @cosme iPhone OS | =2.1 | |
iStyle @cosme iPhone OS | =2.1.1 | |
iStyle @cosme iPhone OS | =2.2 | |
iStyle @cosme iPhone OS | =2.2.1 | |
Apple iPod touch | ||
iStyle @cosme iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1701 is a critical vulnerability that can allow remote attackers to execute arbitrary code or cause denial of service.
To fix CVE-2009-1701, update to the latest version of Apple Safari or the latest iPhone OS.
CVE-2009-1701 affects Apple Safari versions before 4.0, and iPhone OS versions from 1.0 through 2.2.1.
Yes, CVE-2009-1701 can affect iPod touch devices running iPhone OS versions 1.1 through 2.2.1.
CVE-2009-1701 is a use-after-free vulnerability in the JavaScript DOM implementation in WebKit.