CVE-2011-0157: Buffer Overflow
Published Mar 11, 2011
·Updated
WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-09-1.
Affected Software
31 affected components
Apple iPhone OS=3.0
Apple iPhone OS=3.2
Apple iPhone OS=3.1.3
Apple iPhone OS=1.0.2
Apple iPhone OS=4.0.2
Apple iPhone OS=2.2
Apple iPhone OS=1.1.1
Apple iPhone OS=4.1
Apple iPhone OS=2.0.0
Apple iPhone OS=3.1.2
Apple iPhone OS=3.0.1
Apple iPhone OS=1.1.2
Apple iPhone OS=3.1
Apple iPhone OS=1.1.3
Apple iPhone OS=1.1.0
Apple iPhone OS=1.0.1
Apple iPhone OS=2.1
Apple iPhone OS=1.1.5
Apple iPhone OS=4.0.1
Apple iPhone OS=2.1.1
Apple iPhone OS=1.1.4
Apple iPhone OS=1.0.0
Apple iPhone OS=2.0.2
Apple iPhone OS=2.0
Apple WebKit
Apple iPhone OS=2.0.1
Apple iPhone OS=4.0
Apple iPhone OS<=4.2
Apple iPhone OS=2.2.1
Apple iPhone OS=3.2.1
Apple iPhone OS=3.2.2
Event History
Mar 11, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0157?
CVE-2011-0157 is classified as a high severity vulnerability due to its potential to allow execution of arbitrary code.
2
How do I fix CVE-2011-0157?
To fix CVE-2011-0157, update your Apple iOS to version 4.3 or later.
3
What software is affected by CVE-2011-0157?
CVE-2011-0157 affects multiple versions of Apple iPhone OS, including versions 1.0.0 to 4.2.
4
What types of attacks can exploit CVE-2011-0157?
CVE-2011-0157 can be exploited through remote code execution and denial of service attacks.
5
Is CVE-2011-0157 still a concern if my device is updated?
If your device is updated to iOS 4.3 or later, CVE-2011-0157 is no longer a concern.