« Resource Site for "Switchers" Launches | Home | PowerPage Podcast Episode 69 »
February 7, 2008
SecurityFocus Uncovers iPhone Denial of Service Bug
This won't make people happy, but it's important.
SecurityFocus has uncovered a denial of service bug inherent i the iPhone wherein the handset can crash if a user is led to a maliciously crafted web site. The firm has stated that successful attacks can cause a kernel panic and leave the crashed iPhone open to remote code execution.
The bug has been found under both iPhone firmware version 1.1.2 and 1.1.3, which suggests that all released versions of the firmware may also be vulnerable.
Apple's Mobile Safari web browser is vulnerable to the denial-of-service attack, which results from a failure to handle exceptional conditions. The security hole is currently unpatched, leaving iPhone owners vulnerable to potential attacks until Apple issues a security update.
Apple has yet to release an official comment on the situation.
If you've seen this or your end or have ideas for a workaround, let us know over in the comments or forums.
Posted by chrisbarylick at February 7, 2008 1:55 PM
Category: iPhone
Buy from: Apple, iTunes
, Amazon
.
Digg This |
Post to del.icio.us |
Post to Furl
- Reminder: PPUG Meets tomorrow 26 July in Philly
- Intel May Offer System-On-A-Chip, Dual-Core Atom Processors for Apple Products
- Rumor: Orange May Offer iPhone in UK Come October
- iPhone OS 2.1 Enters Beta Testing
- Apple Releases AirPort Extreme Update 2008 - 002
- MobileMe Problems Discovered, Solutions Offered
- Security Researcher Warns of Unpatched iPhone Bugs
- Mozilla Releases Thunderbird 2.0.0.16
- Apple May Release Product Red iPhone for Holidays
- PowerPage Podcast Episode 85
- AT&T Currently Developing Voice-Controlled iPhone Applications
- Rumor: Apple May Release Sub-US$1,000 Notebook Later This Year
- Apple Releases iLife Support 8.3 Update
- Apple Releases iPhoto 7.1.4 Update
- Sybase Announces Lotus Notes, Microsoft Exchange Support for iPhone 3G
Trackback Pings
TrackBack URL for this entry:
http://www.powerpage.org/mt/mt-tb.cgi/10969










