First published: Fri Oct 14 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | =4.0 | |
iPhone OS | =4.3.2 | |
iPhone OS | =4.0.2 | |
iPhone OS | =4.0.1 | |
iPhone OS | =3.2 | |
iPhone OS | =4.2.8 | |
iPhone OS | =4.1 | |
iPhone OS | =3.1.2 | |
iPhone OS | =4.3.5 | |
iPhone OS | =3.1.3 | |
iPhone OS | =4.3.1 | |
iPhone OS | =4.2.5 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.1 | |
iPhone OS | =4.3.5 | |
iPhone OS | =3.1 | |
iPhone OS | =3.2 | |
iPhone OS | =4.3.5 | |
iPhone OS | =4.2.1 | |
iPhone OS | =3.0 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.3.3 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.0 | |
iPhone OS | =3.1 | |
iPhone OS | =4.0 | |
iPhone OS | =4.3.0 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3426 is categorized as moderate due to its ability to facilitate cross-site scripting attacks.
To fix CVE-2011-3426, you should upgrade to iOS version 5 or later where the vulnerability has been addressed.
CVE-2011-3426 affects Apple iOS versions 4.0, 4.0.1, 4.0.2, 4.1, 4.2.x, 4.3.x, and earlier.
CVE-2011-3426 allows remote web servers to inject arbitrary web script or HTML into Safari on affected devices.
CVE-2011-3426 is less of a concern for users on current iOS versions, but still poses a risk for those using outdated systems.