First published: Thu Sep 20 2012(Updated: )
UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a device's filesystem.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=5.1.1 | |
iPhone OS | =1.0.0 | |
iPhone OS | =1.0.1 | |
iPhone OS | =1.0.2 | |
iPhone OS | =1.1.0 | |
iPhone OS | =1.1.1 | |
iPhone OS | =1.1.2 | |
iPhone OS | =1.1.3 | |
iPhone OS | =1.1.4 | |
iPhone OS | =1.1.5 | |
iPhone OS | =2.0 | |
iPhone OS | =2.0.0 | |
iPhone OS | =2.0.1 | |
iPhone OS | =2.0.2 | |
iPhone OS | =2.1 | |
iPhone OS | =2.1.1 | |
iPhone OS | =2.2 | |
iPhone OS | =2.2.1 | |
iPhone OS | =3.0 | |
iPhone OS | =3.0.1 | |
iPhone OS | =3.1 | |
iPhone OS | =3.1.2 | |
iPhone OS | =3.1.3 | |
iPhone OS | =3.2 | |
iPhone OS | =3.2.1 | |
iPhone OS | =3.2.2 | |
iPhone OS | =4.0 | |
iPhone OS | =4.0.1 | |
iPhone OS | =4.0.2 | |
iPhone OS | =4.1 | |
iPhone OS | =4.2.1 | |
iPhone OS | =4.2.5 | |
iPhone OS | =4.2.8 | |
iPhone OS | =4.3.0 | |
iPhone OS | =4.3.1 | |
iPhone OS | =4.3.2 | |
iPhone OS | =4.3.3 | |
iPhone OS | =4.3.5 | |
iPhone OS | =5.0 | |
iPhone OS | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3746 has a moderate severity level as it allows unauthorized access to sensitive file contents.
To address CVE-2012-3746, users should upgrade their devices to iOS 6 or later, which resolves the vulnerability.
CVE-2012-3746 enables context-dependent attackers to access cleartext file content through unauthorized direct filesystem access.
Users of Apple iOS versions prior to 6, including various versions from 1.0.0 to 5.1.1, are affected by CVE-2012-3746.
CVE-2012-3746 impacts the UIWebView component within the UIKit framework of affected iOS versions.