First published: Sat Nov 03 2012(Updated: )
Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <=6.0.1 | |
Apple Mobile Safari | =1.0-beta | |
Apple Mobile Safari | =1.0-beta2 | |
Apple Mobile Safari | =1.0.0 | |
Apple Mobile Safari | =1.0.0b1 | |
Apple Mobile Safari | =1.0.0b2 | |
Apple Mobile Safari | =1.0.1 | |
Apple Mobile Safari | =1.0.2 | |
Apple Mobile Safari | =1.0.3 | |
Apple Mobile Safari | =1.1.0 | |
Apple Mobile Safari | =1.1.1 | |
Apple Mobile Safari | =1.2.0 | |
Apple Mobile Safari | =1.2.1 | |
Apple Mobile Safari | =1.2.2 | |
Apple Mobile Safari | =1.2.3 | |
Apple Mobile Safari | =1.2.4 | |
Apple Mobile Safari | =1.2.5 | |
Apple Mobile Safari | =1.3 | |
Apple Mobile Safari | =1.3.0 | |
Apple Mobile Safari | =1.3.1 | |
Apple Mobile Safari | =1.3.2 | |
Apple Mobile Safari | =2.0.0 | |
Apple Mobile Safari | =2.0.1 | |
Apple Mobile Safari | =2.0.2 | |
Apple Mobile Safari | =2.0.3 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =3.0.0 | |
Apple Mobile Safari | =3.0.0b | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.0.1-beta | |
Apple Mobile Safari | =3.0.1b | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =3.0.2b | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =3.0.3b | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =3.0.4b | |
Apple Mobile Safari | =3.1.0 | |
Apple Mobile Safari | =3.1.0b | |
Apple Mobile Safari | =3.1.1 | |
Apple Mobile Safari | =3.1.2 | |
Apple Mobile Safari | =3.2.0 | |
Apple Mobile Safari | =3.2.1 | |
Apple Mobile Safari | =3.2.2 | |
Apple Mobile Safari | =4.0 | |
Apple Mobile Safari | =4.0-beta | |
Apple Mobile Safari | =4.0.0b | |
Apple Mobile Safari | =4.0.1 | |
Apple Mobile Safari | =4.0.2 | |
Apple Mobile Safari | =4.0.3 | |
Apple Mobile Safari | =4.0.4 | |
Apple Mobile Safari | =4.0.5 | |
Apple Mobile Safari | =4.1 | |
Apple Mobile Safari | =4.1.1 | |
Apple Mobile Safari | =4.1.2 | |
Apple Mobile Safari | =5.0 | |
Apple Mobile Safari | =5.0.1 | |
Apple Mobile Safari | =5.0.2 | |
Apple Mobile Safari | =5.0.4 | |
Apple Mobile Safari | =5.0.5 | |
Apple Mobile Safari | =5.0.6 | |
Apple Mobile Safari | =5.1 | |
Apple Mobile Safari | =5.1.1 | |
Apple Mobile Safari | =5.1.2 | |
Apple Mobile Safari | =5.1.3 | |
Apple Mobile Safari | =5.1.4 | |
Apple Mobile Safari | =5.1.5 | |
Apple Mobile Safari | =5.1.6 | |
Apple Mobile Safari | =5.1.7 | |
Apple Mobile Safari | =6.0 | |
iStyle @cosme iPhone OS | <=6.0 | |
iStyle @cosme iPhone OS | =1.0.0 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.0 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
iStyle @cosme iPhone OS | =1.1.3 | |
iStyle @cosme iPhone OS | =1.1.4 | |
iStyle @cosme iPhone OS | =1.1.5 | |
iStyle @cosme iPhone OS | =2.0 | |
iStyle @cosme iPhone OS | =2.0.0 | |
iStyle @cosme iPhone OS | =2.0.1 | |
iStyle @cosme iPhone OS | =2.0.2 | |
iStyle @cosme iPhone OS | =2.1 | |
iStyle @cosme iPhone OS | =2.1.1 | |
iStyle @cosme iPhone OS | =2.2 | |
iStyle @cosme iPhone OS | =2.2.1 | |
iStyle @cosme iPhone OS | =3.0 | |
iStyle @cosme iPhone OS | =3.0.1 | |
iStyle @cosme iPhone OS | =3.1 | |
iStyle @cosme iPhone OS | =3.1.2 | |
iStyle @cosme iPhone OS | =3.1.3 | |
iStyle @cosme iPhone OS | =3.2 | |
iStyle @cosme iPhone OS | =3.2.1 | |
iStyle @cosme iPhone OS | =3.2.2 | |
iStyle @cosme iPhone OS | =4.0 | |
iStyle @cosme iPhone OS | =4.0.1 | |
iStyle @cosme iPhone OS | =4.0.2 | |
iStyle @cosme iPhone OS | =4.1 | |
iStyle @cosme iPhone OS | =4.2.1 | |
iStyle @cosme iPhone OS | =4.2.5 | |
iStyle @cosme iPhone OS | =4.2.8 | |
iStyle @cosme iPhone OS | =4.3.0 | |
iStyle @cosme iPhone OS | =4.3.1 | |
iStyle @cosme iPhone OS | =4.3.2 | |
iStyle @cosme iPhone OS | =4.3.3 | |
iStyle @cosme iPhone OS | =4.3.5 | |
iStyle @cosme iPhone OS | =5.0 | |
iStyle @cosme iPhone OS | =5.0.1 | |
iStyle @cosme iPhone OS | =5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3748 has a high severity rating due to its potential to allow remote code execution and application crashes.
To fix CVE-2012-3748, users should update to Apple iOS versions 6.0.1 or later and Safari versions 6.0.2 or later.
CVE-2012-3748 affects various versions of Apple Safari and iPhone OS prior to their secure updates.
CVE-2012-3748 can be exploited through specially crafted JavaScript that manipulates arrays, leading to arbitrary code execution.
While the best solution is to update the software, temporary mitigation strategies include disabling JavaScript in Safari.