CVE-2009-3271: Input Validation
Published Sep 21, 2009
·Updated
Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.
Affected Software
2 affected components
Safari
iPhone OS=3.0.1
Event History
Sep 21, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3271?
CVE-2009-3271 has a medium severity rating, as it allows for denial of service attacks resulting in application crashes.
2
How do I fix CVE-2009-3271?
To mitigate CVE-2009-3271, users should update to a later version of Apple Safari or iPhone OS that does not include this vulnerability.
3
What systems are affected by CVE-2009-3271?
CVE-2009-3271 specifically affects Apple Safari on iPhone OS version 3.0.1.
4
What type of attack is associated with CVE-2009-3271?
CVE-2009-3271 is associated with denial of service attacks triggered by a malicious long tel: URL in an IFRAME.
5
Can CVE-2009-3271 be exploited remotely?
Yes, CVE-2009-3271 can be exploited remotely, allowing attackers to cause application crashes from afar.