First published: Fri Oct 14 2011(Updated: )
CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | =4.0 | |
iPhone OS | =4.3.2 | |
iPhone OS | =4.0.2 | |
iPhone OS | =4.0.1 | |
iPhone OS | =3.2 | |
iPhone OS | =4.2.8 | |
iPhone OS | =4.1 | |
iPhone OS | =3.1.2 | |
iPhone OS | =4.3.5 | |
iPhone OS | =3.1.3 | |
iPhone OS | =4.3.1 | |
iPhone OS | =4.2.5 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.1 | |
iPhone OS | =4.3.5 | |
iPhone OS | =3.1 | |
iPhone OS | =3.2 | |
iPhone OS | =4.3.5 | |
iPhone OS | =4.2.1 | |
iPhone OS | =3.0 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.3.3 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.0 | |
iPhone OS | =3.1 | |
iPhone OS | =4.0 | |
iPhone OS | =4.3.0 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3255 has been assigned a medium severity rating due to potential unauthorized access to AppleID credentials.
To fix CVE-2011-3255, users should update their Apple iOS devices to a version 5 or higher.
CVE-2011-3255 affects Apple iOS versions up to 4.3.5, including versions 3.0 through 4.3.5.
CVE-2011-3255 can lead to the compromise of AppleID credentials stored in an insecure file.
Yes, CVE-2011-3255 can be exploited by remote attackers through crafted applications that access stored AppleID credentials.