CVE-2011-3442: High severity iphone os vulnerability
Published Nov 11, 2011
·Updated
The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.
Affected Software
12 affected components
apple iPhone OS=4.3.2
apple iPhone OS=5.0
apple iPhone OS=4.3.4
apple iPhone OS=4.3.5
apple iPhone OS=4.3.1
apple iPhone OS=4.3.5
apple iPhone OS=4.3.5
apple iPhone OS=5.0
apple iPhone OS=4.3.3
apple iPhone OS=5.0
apple iPhone OS=5.0
apple iPhone OS=4.3.0
Event History
Nov 11, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3442?
CVE-2011-3442 is classified as a high-severity vulnerability due to its potential to allow local users to execute arbitrary unsigned code.
2
How do I fix CVE-2011-3442?
To mitigate CVE-2011-3442, update your Apple iOS to version 5.0.1 or later.
3
Which iOS versions are affected by CVE-2011-3442?
CVE-2011-3442 affects Apple iOS versions 4.3.0 to 5.0, including iPhones, iPads, and iPod Touch devices.
4
Can CVE-2011-3442 be exploited remotely?
No, CVE-2011-3442 can only be exploited locally by users with access to the affected device.
5
What types of devices are impacted by CVE-2011-3442?
CVE-2011-3442 impacts various Apple devices running iOS, including iPhones, iPads, and iPod Touch models.