Vulnerability Name: | CVE-2009-0960 (CCN-51209) |
Assigned: | 2009-06-17 |
Published: | 2009-06-17 |
Updated: | 2022-08-09 |
Summary: | The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2009-0960
Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2009-06-17-1
Source: CCN Type: SA35449 Apple iPhone / iPod touch Multiple Vulnerabilities
Source: CCN Type: Apple Web site About the security content of iPhone OS 3.0 Software Update
Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT3639
Source: CCN Type: OSVDB ID: 56456 Apple iPhone / iPod Mail Component HTML Image Referer Information Disclosure
Source: BID Type: UNKNOWN 35414
Source: CCN Type: BID-35414 RETIRED: Apple iPhone and iPod touch Prior to Version 3.0 Multiple Vulnerabilities
Source: BID Type: UNKNOWN 35434
Source: CCN Type: BID-35434 Apple iPhone and iPod touch Mail Client Information Disclosure Weakness
Source: VUPEN Type: Vendor Advisory ADV-2009-1621
Source: XF Type: UNKNOWN iphone-ipod-mail-weak-security(51209)
Source: XF Type: UNKNOWN iphone-ipod-mail-weak-security(51209)
|
Vulnerable Configuration: | Configuration 1: cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*AND cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* Configuration 2: cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*AND cpe:/h:apple:ipod_touch:*:*:*:*:*:*:*:* Configuration CCN 1: cpe:/o:apple:iphone_os:1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.3:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |