First published: Thu Mar 08 2012(Updated: )
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <5.1 | |
iTunes | <10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2873 has a moderate severity rating due to its potential for remote code execution and denial of service.
To mitigate CVE-2011-2873, users should update their iOS to version 5.1 and iTunes to version 10.6 or later.
CVE-2011-2873 affects devices running older versions of iOS prior to 5.1 and iTunes versions before 10.6.
The risks include potential arbitrary code execution and application crashes resulting from memory corruption.
Yes, attackers can exploit CVE-2011-2873 remotely through a maliciously crafted website.