CVE-2009-2815: Null Pointer Dereference
Published Sep 10, 2009
·Updated
The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.
Affected Software
21 affected components
apple iPhone OS=3.0
apple iPhone OS=1.0.2
apple iPhone OS=1.0
apple iPhone OS=2.2
apple iPhone OS<=3.0.1
apple iPhone OS=1.1.1
apple iPhone OS=2.0.0
apple iPhone OS=1.1.2
apple iPhone OS=1.1.3
apple iPhone OS=1.1
apple iPhone OS=1.1.0
apple iPhone OS=1.0.1
apple iPhone OS=2.1
apple iPhone OS=1.1.5
apple iPhone OS=2.1.1
apple iPhone OS=1.1.4
apple iPhone OS=1.0.0
apple iPhone OS=2.0.2
apple iPhone OS=2.0
apple iPhone OS=2.0.1
apple iPhone OS=2.2.1
Remediation
Patch Available
Event History
Sep 10, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2815?
CVE-2009-2815 has been classified as a denial of service vulnerability that can interrupt service due to a NULL pointer dereference.
2
How do I fix CVE-2009-2815?
To mitigate CVE-2009-2815, users should upgrade to iPhone OS version 3.1 or later.
3
What systems are affected by CVE-2009-2815?
CVE-2009-2815 affects multiple versions of Apple iPhone OS prior to 3.1.
4
What type of attack is associated with CVE-2009-2815?
CVE-2009-2815 enables remote attackers to send crafted SMS messages leading to service disruption.
5
Is CVE-2009-2815 a local or remote vulnerability?
CVE-2009-2815 is a remote vulnerability, exploitable via crafted SMS messages.