|
Brought to you by:
Suppliers of:
|
|
|
| |
| Calling the CSS attr() attribute with a large number leads to memory corruption, heap spraying allows execution of code. |
| |
Credit:
The information has been provided by Thierry at zoller.lu.
The original article can be found at: http://www.g-sec.lu/iphone-remote-code-exec.html
|
| |
Vulnerable Systems:
* Apple iPhone OS 1.x through 2.2.1
* Apple iPhone OS for iPod touch 1.x through 2.2.1
Calling the CSS attr() attribute with a large number leads to memory corruption, heap spraying allows execution of code.
Arbitrary remote code execution can be achieved by creating a special website and entice the victim into visiting that site.
CVE Information:
CVE-2009-1698
|
|
blog comments powered by
|
|
|