First published: Fri Nov 26 2010(Updated: )
Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | =3.0 | |
iPhone OS | =3.2 | |
iPhone OS | =3.1.3 | |
iPhone OS | =1.0.2 | |
iPhone OS | =4.0.2 | |
iPhone OS | =2.2 | |
iPhone OS | =1.1.1 | |
iPhone OS | <=4.1 | |
iPhone OS | =2.0.0 | |
iPhone OS | =3.1.2 | |
iPhone OS | =3.0.1 | |
iPhone OS | =1.1.2 | |
iPhone OS | =3.1 | |
iPhone OS | =1.1.3 | |
iPhone OS | =1.1.0 | |
iPhone OS | =1.0.1 | |
iPhone OS | =2.1 | |
iPhone OS | =1.1.5 | |
iPhone OS | =4.0.1 | |
iPhone OS | =2.1.1 | |
iPhone OS | =1.1.4 | |
iPhone OS | =1.0.0 | |
iPhone OS | =2.0.2 | |
iPhone OS | =2.0 | |
iPhone OS | =2.0.1 | |
iPhone OS | =4.0 | |
iPhone OS | =2.2.1 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3827 is classified as a medium severity vulnerability due to its potential for profile spoofing.
To remedy CVE-2010-3827, users are advised to upgrade to Apple iOS 4.2 or later versions.
CVE-2010-3827 affects various Apple iOS devices running versions prior to 4.2.
CVE-2010-3827 poses risks of remote attackers being able to spoof configuration profiles on vulnerable devices.
CVE-2010-3827 was published on November 10, 2010.