CVE-2011-3432: Medium severity iphone os vulnerability
Published Oct 14, 2011
·Updated
The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.
Affected Software
29 affected components
apple iPhone OS=4.0
apple iPhone OS=4.3.2
apple iPhone OS=4.0.2
apple iPhone OS=4.0.1
apple iPhone OS=3.2
apple iPhone OS=4.2.8
apple iPhone OS=4.1
apple iPhone OS=3.1.2
apple iPhone OS=4.3.5
apple iPhone OS=3.1.3
apple iPhone OS=4.3.1
apple iPhone OS=4.2.5
apple iPhone OS=3.2.1
apple iPhone OS=3.1
apple iPhone OS=4.3.5
apple iPhone OS=3.1
apple iPhone OS=3.2
apple iPhone OS=4.3.5
apple iPhone OS=4.2.1
apple iPhone OS=3.0
apple iPhone OS=4.0.1
apple iPhone OS=4.3.3
apple iPhone OS=4.0.1
apple iPhone OS=4.0
apple iPhone OS=3.1
apple iPhone OS=4.0
apple iPhone OS=4.3.0
apple iPhone OS=3.2.1
apple iPhone OS=3.2.2
Event History
Oct 14, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3432?
CVE-2011-3432 has been classified as a denial of service vulnerability that can cause device hangs.
2
How do I fix CVE-2011-3432?
Mitigation of CVE-2011-3432 can be achieved by upgrading to iOS version 5 or later.
3
Which versions of Apple iOS are affected by CVE-2011-3432?
CVE-2011-3432 affects various iOS versions including 4.0, 4.0.1, 4.2.5, and 3.2 among others.
4
Can CVE-2011-3432 be exploited remotely?
Yes, CVE-2011-3432 can be exploited remotely via specially crafted long tel: URLs.
5
What impact does CVE-2011-3432 have on users?
The impact of CVE-2011-3432 is a denial of service condition, potentially causing the device to become unresponsive.