First published: Fri Nov 26 2010(Updated: )
Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber Identity (TMSI) field.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=4.1 | |
iStyle @cosme iPhone OS | =1.0.0 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.0 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
iStyle @cosme iPhone OS | =1.1.3 | |
iStyle @cosme iPhone OS | =1.1.4 | |
iStyle @cosme iPhone OS | =1.1.5 | |
iStyle @cosme iPhone OS | =2.0 | |
iStyle @cosme iPhone OS | =2.0.0 | |
iStyle @cosme iPhone OS | =2.0.1 | |
iStyle @cosme iPhone OS | =2.0.2 | |
iStyle @cosme iPhone OS | =2.1 | |
iStyle @cosme iPhone OS | =2.1.1 | |
iStyle @cosme iPhone OS | =2.2 | |
iStyle @cosme iPhone OS | =2.2.1 | |
iStyle @cosme iPhone OS | =3.0 | |
iStyle @cosme iPhone OS | =3.0.1 | |
iStyle @cosme iPhone OS | =3.1 | |
iStyle @cosme iPhone OS | =3.1.2 | |
iStyle @cosme iPhone OS | =3.1.3 | |
iStyle @cosme iPhone OS | =3.2 | |
iStyle @cosme iPhone OS | =3.2.1 | |
iStyle @cosme iPhone OS | =3.2.2 | |
iStyle @cosme iPhone OS | =4.0 | |
iStyle @cosme iPhone OS | =4.0.1 | |
iStyle @cosme iPhone OS | =4.0.2 | |
Apple iPad | ||
iStyle @cosme iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3832 is categorized as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2010-3832, you should update your Apple iOS to version 4.2 or later.
CVE-2010-3832 affects Apple iOS versions prior to 4.2, including all versions up to 4.1.
CVE-2010-3832 is a heap-based buffer overflow vulnerability located in the GSM mobility management implementation.
Attackers can execute arbitrary code on the baseband processor using a crafted Temporary Mobile Subscriber Identity (TMSI) field.