CVE-2009-2796: Infoleak
Published Sep 10, 2009
·Updated
The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.
Affected Software
2 affected components
apple iPhone OS=3.0
apple iPhone OS=3.0.1
Remediation
Patch Available
Event History
Sep 10, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2796?
CVE-2009-2796 is considered a medium severity vulnerability due to the risk of password exposure.
2
How do I fix CVE-2009-2796?
To fix CVE-2009-2796, users should upgrade to a later version of iPhone OS that addresses this issue.
3
What devices are affected by CVE-2009-2796?
CVE-2009-2796 affects devices running iPhone OS 3.0 and 3.0.1, including the iPhone and iPod Touch.
4
What type of attack does CVE-2009-2796 enable?
CVE-2009-2796 enables physically proximate attackers to discover a user's password through observation.
5
Is there a workaround for CVE-2009-2796?
There is no official workaround for CVE-2009-2796 other than upgrading to a more secure version of iPhone OS.