First published: Fri Oct 14 2011(Updated: )
The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | =4.0 | |
Apple iPhone OS | =4.3.2 | |
Apple iPhone OS | =4.0.2 | |
Apple iPhone OS | =4.0.1 | |
Apple iPhone OS | =3.2 | |
Apple iPhone OS | =4.2.8 | |
Apple iPhone OS | =4.1 | |
Apple iPhone OS | =3.1.2 | |
Apple iPhone OS | =4.3.5 | |
Apple iPhone OS | =3.1.3 | |
Apple iPhone OS | =4.3.1 | |
Apple iPhone OS | =4.2.5 | |
Apple iPhone OS | =3.2.1 | |
Apple iPhone OS | =3.1 | |
Apple iPhone OS | =4.3.5 | |
Apple iPhone OS | =3.1 | |
Apple iPhone OS | =3.2 | |
Apple iPhone OS | =4.3.5 | |
Apple iPhone OS | =4.2.1 | |
Apple iPhone OS | =3.0 | |
Apple iPhone OS | =4.0.1 | |
Apple iPhone OS | =4.3.3 | |
Apple iPhone OS | =4.0.1 | |
Apple iPhone OS | =4.0 | |
Apple iPhone OS | =3.1 | |
Apple iPhone OS | =4.0 | |
Apple iPhone OS | =4.3.0 | |
Apple iPhone OS | =3.2.1 | |
Apple iPhone OS | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3245 is considered a medium severity vulnerability due to the potential for sensitive information disclosure.
To resolve CVE-2011-3245, users should update their Apple iOS devices to version 5 or later, where the issue is addressed.
CVE-2011-3245 affects Apple iOS versions prior to 5, including versions 3.1 to 4.3.5.
CVE-2011-3245 can expose the final character of an entered password during subsequent keyboard use.
Physically proximate attackers can easily exploit CVE-2011-3245 to retrieve sensitive information from devices that are running vulnerable versions of iOS.