CVE-2010-1757: Medium severity iphone os vulnerability
Published Jun 22, 2010
·Updated
WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.
Affected Software
3 affected components
apple iPhone OS<4.0
Apple iPod touch
apple iPhone OS
Event History
Jun 22, 2010
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
Description
Data Sourced
08:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1757?
CVE-2010-1757 is classified as a medium severity vulnerability.
2
How does CVE-2010-1757 affect Apple iOS devices?
CVE-2010-1757 allows remote attackers to spoof the user interface on Apple iOS devices by exploiting the IFRAME boundary restrictions.
3
Which versions of Apple iOS are affected by CVE-2010-1757?
CVE-2010-1757 affects Apple iOS versions prior to 4.0 on iPhone and iPod touch.
4
How can I fix the vulnerability identified by CVE-2010-1757?
To fix CVE-2010-1757, users should update their Apple iOS devices to version 4.0 or later.
5
What type of attack is possible with CVE-2010-1757?
CVE-2010-1757 enables attackers to perform user interface spoofing through a crafted HTML document.