CVE-2012-3724: Infoleak
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3724?
CVE-2012-3724 has been classified as a moderate severity vulnerability, allowing sensitive information disclosure under specific conditions.
How do I fix CVE-2012-3724?
To fix CVE-2012-3724, update your Apple iOS device to version 6 or later, as this vulnerability is addressed in that update.
What devices are affected by CVE-2012-3724?
CVE-2012-3724 affects Apple iOS devices running versions prior to 6, including those up to 5.1.1.
What type of attack does CVE-2012-3724 facilitate?
CVE-2012-3724 facilitates attacks where remote attackers can exploit malformed URLs to obtain sensitive information.
Is it possible to exploit CVE-2012-3724 remotely?
Yes, CVE-2012-3724 can be exploited remotely by crafting malicious HTTP requests with malformed URLs.