VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3832
iphone_os: Heap-based buffer overflow in the GSM mobility mana...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3832

Original

Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband processor via a crafted Temporary Mobile Subscriber Identity (TMSI) field.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-11-26
Source Information Category:
Advisory, Alert
Last Updated:
2010-11-29




Affected Product Tags
cpe:/h:apple:ipad
cpe:/h:apple:iphone
cpe:/o:apple:iphone_os:1.0.0
cpe:/o:apple:iphone_os:1.0.1
cpe:/o:apple:iphone_os:1.0.2
cpe:/o:apple:iphone_os:1.1.0
cpe:/o:apple:iphone_os:1.1.1
cpe:/o:apple:iphone_os:1.1.2
cpe:/o:apple:iphone_os:1.1.3
cpe:/o:apple:iphone_os:1.1.4
cpe:/o:apple:iphone_os:1.1.5
cpe:/o:apple:iphone_os:2.0
cpe:/o:apple:iphone_os:2.0.0
cpe:/o:apple:iphone_os:2.0.1
cpe:/o:apple:iphone_os:2.0.2
cpe:/o:apple:iphone_os:2.1
cpe:/o:apple:iphone_os:2.1.1
cpe:/o:apple:iphone_os:2.2
cpe:/o:apple:iphone_os:2.2.1
cpe:/o:apple:iphone_os:3.0
cpe:/o:apple:iphone_os:3.0.1
cpe:/o:apple:iphone_os:3.1
cpe:/o:apple:iphone_os:3.1.2
cpe:/o:apple:iphone_os:3.1.3
cpe:/o:apple:iphone_os:3.2
cpe:/o:apple:iphone_os:3.2.1
cpe:/o:apple:iphone_os:3.2.2
cpe:/o:apple:iphone_os:4.0
cpe:/o:apple:iphone_os:4.0.1
cpe:/o:apple:iphone_os:4.0.2
cpe:/o:apple:iphone_os:4.1 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
APPLE APPLE-SA-2010-11-22-1




CONFIRM http://support.apple.com/kb/HT4456




Vulnerability Type Buffer Errors (CWE-119)





Copyright © 2010 JPCERT/CC All Rights Reserved.