First published: Tue Jan 29 2013(Updated: )
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=6.0.2 | |
iPhone OS | =6.0 | |
iPhone OS | =6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0954 has a high severity level due to the potential for remote code execution and denial of service.
To fix CVE-2013-0954, update your device to iOS version 6.1 or later.
CVE-2013-0954 affects Apple iOS versions before 6.1, including 6.0 and 6.0.1.
Risks associated with CVE-2013-0954 include the ability for attackers to execute arbitrary code and cause application crashes.
There are no official workarounds for CVE-2013-0954; upgrading to a secure version is the only solution.