Vulnerability Name:
CVE-2009-0959 (CCN-51211)
Assigned:
2009-06-17
Published:
2009-06-17
Updated:
2022-08-09
Summary:
The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted MPEG-4 video file that triggers an "input validation issue."
CVSS v3 Severity:
5.3 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Low
CVSS v2 Severity:
7.1 High
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C
)
5.3 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Complete
4.3 Medium
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P
)
3.2 Low
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
Vulnerability Type:
CWE-20
Vulnerability Consequences:
Denial of Service
References:
Source: MITRE
Type: CNA
CVE-2009-0959
Source: APPLE
Type: Vendor Advisory
APPLE-SA-2009-06-17-1
Source: OSVDB
Type: UNKNOWN
55237
Source: CCN
Type: SA35449
Apple iPhone / iPod touch Multiple Vulnerabilities
Source: CCN
Type: Apple Web site
About the security content of iPhone OS 3.0 Software Update
Source: CONFIRM
Type: Patch, Vendor Advisory
http://support.apple.com/kb/HT3639
Source: CCN
Type: OSVDB ID: 55237
Apple iPhone / iPod Touch MPEG-4 Video Codec Crafted Video File Handling DoS
Source: BID
Type: UNKNOWN
35414
Source: CCN
Type: BID-35414
RETIRED: Apple iPhone and iPod touch Prior to Version 3.0 Multiple Vulnerabilities
Source: BID
Type: UNKNOWN
35433
Source: CCN
Type: BID-35433
Apple iPhone and iPod touch MPEG-4 Video Codec Denial of Service Vulnerability
Source: VUPEN
Type: Vendor Advisory
ADV-2009-1621
Source: XF
Type: UNKNOWN
ipod-iphone-mpeg4-dos(51211)
Source: XF
Type: UNKNOWN
ipod-iphone-mpeg4-dos(51211)
Vulnerable Configuration:
Configuration 1
:
cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
AND
cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:*
Configuration 2
:
cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
AND
cpe:/h:apple:ipod_touch:*:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/o:apple:iphone_os:1.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.3:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
apple
iphone os 1.0.2
apple
iphone os 2.2
apple
iphone os 1.1.1
apple
iphone os 2.0.0
apple
iphone os 1.1.2
apple
iphone os 1.1.3
apple
iphone os 1.1.0
apple
iphone os 1.0.1
apple
iphone os 2.1
apple
iphone os 2.1.1
apple
iphone os 2.0.2
apple
iphone os 2.0.1
apple
iphone os 2.2.1
apple
iphone os 1.1.5
apple
iphone os 1.1.4
apple
iphone os 1.0.0
apple
iphone os 2.0
apple
iphone os *
apple
iphone os 2.2
apple
iphone os 1.1.1
apple
iphone os 2.0.0
apple
iphone os 1.1.2
apple
iphone os 1.1.3
apple
iphone os 1.1.0
apple
iphone os 2.1
apple
iphone os 1.1.5
apple
iphone os 2.1.1
apple
iphone os 2.0
apple
iphone os 2.2.1
apple
iphone os 1.1.4
apple
iphone os 2.0.2
apple
iphone os 2.0.1
apple
ipod touch *
apple
iphone 1.0
apple
iphone 1.1.2
apple
iphone 1.1.3
apple
iphone 1.0.1
apple
iphone 1.0.2
apple
iphone 1.02
apple
iphone 1.1.1
apple
ipod touch 1.1
apple
ipod touch 1.1.1
apple
ipod touch 1.1.2
apple
iphone 1.1.4
apple
ipod touch 1.1.3
apple
ipod touch 1.1.4
apple
iphone 2.0.2
apple
ipod touch 2.0.2
apple
ipod touch 2.0.1
apple
ipod touch 2.0
apple
iphone 2.0
apple
iphone 2.0.1
apple
iphone 2.1
apple
iphone 1.1
apple
iphone os 2.2
apple
iphone os 2.2.1