First published: Thu Sep 10 2009(Updated: )
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | =2.0.2 | |
iPhone OS | =3.0 | |
iPhone OS | =2.2 | |
iPhone OS | =3.0.1 | |
iPhone OS | =2.0.1 | |
iPhone OS | =2.1 | |
iPhone OS | =3.0 | |
iPhone OS | =2.2.1 | |
iPhone OS | =2.2 | |
iPhone OS | =2.1.1 | |
iPhone OS | =2.0.0 | |
iPhone OS | =2.0.2 | |
iPhone OS | =2.0 | |
iPhone OS | =2.0.1 | |
iPhone OS | =2.2.1 | |
iPhone OS | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2794 is considered a medium severity vulnerability due to its potential to allow unauthorized access to Exchange mail accounts.
To fix CVE-2009-2794, update your Apple iPhone OS to version 3.1 or later.
CVE-2009-2794 affects Apple iPhone OS versions prior to 3.1 and some versions of iPod touch.
CVE-2009-2794 can be exploited locally by bypassing the Maximum inactivity time lock feature.
Local users of affected iPhone and iPod touch devices may be impacted by CVE-2009-2794.