First published: Thu Sep 10 2009(Updated: )
The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | =3.0 | |
iPhone OS | =1.0.2 | |
iPhone OS | =1.0 | |
iPhone OS | =2.2 | |
iPhone OS | <=3.0.1 | |
iPhone OS | =1.1.1 | |
iPhone OS | =2.0.0 | |
iPhone OS | =1.1.2 | |
iPhone OS | =1.1.3 | |
iPhone OS | =1.1 | |
iPhone OS | =1.1.0 | |
iPhone OS | =1.0.1 | |
iPhone OS | =2.1 | |
iPhone OS | =1.1.5 | |
iPhone OS | =2.1.1 | |
iPhone OS | =1.1.4 | |
iPhone OS | =1.0.0 | |
iPhone OS | =2.0.2 | |
iPhone OS | =2.0 | |
iPhone OS | =2.0.1 | |
iPhone OS | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2815 has been classified as a denial of service vulnerability that can interrupt service due to a NULL pointer dereference.
To mitigate CVE-2009-2815, users should upgrade to iPhone OS version 3.1 or later.
CVE-2009-2815 affects multiple versions of Apple iPhone OS prior to 3.1.
CVE-2009-2815 enables remote attackers to send crafted SMS messages leading to service disruption.
CVE-2009-2815 is a remote vulnerability, exploitable via crafted SMS messages.