Vulnerability Name: | CVE-2009-0961 (CCN-51210) |
Assigned: | 2009-06-17 |
Published: | 2009-06-17 |
Updated: | 2022-08-09 |
Summary: | The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2009-0961
Source: APPLE Type: Vendor Advisory APPLE-SA-2009-06-17-1
Source: OSVDB Type: UNKNOWN 55238
Source: CCN Type: SA35449 Apple iPhone / iPod touch Multiple Vulnerabilities
Source: CCN Type: Apple Web site About the security content of iPhone OS 3.0 Software Update
Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT3639
Source: CCN Type: OSVDB ID: 55238 Apple iPhone / iPod Touch Mail Call Approval Dialog Alert Handling Arbitrary Outgoing Call Initiation
Source: BID Type: UNKNOWN 35414
Source: CCN Type: BID-35414 RETIRED: Apple iPhone and iPod touch Prior to Version 3.0 Multiple Vulnerabilities
Source: CCN Type: BID-35425 Apple iPhone Call Approval Dialog Security Bypass Vulnerability
Source: VUPEN Type: UNKNOWN ADV-2009-1621
Source: XF Type: UNKNOWN iphone-ipod-mail-security-bypass(51210)
Source: XF Type: UNKNOWN iphone-ipod-mail-security-bypass(51210)
|
Vulnerable Configuration: | Configuration 1: cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*AND cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* Configuration 2: cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*AND cpe:/h:apple:ipod_touch:*:*:*:*:*:*:*:* Configuration CCN 1: cpe:/o:apple:iphone_os:1.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.3:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*OR cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:1.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |