Apple patches 10 iPhone flaws

Apple today released ten iPhone security updates, including seven within the MobileSafari browser.

The update is available only through iTunes and is not available from the Apple Downloads page. The version users should see within their iPhone after applying this update should be 1.1.1 (3A109a).

Apple refuses to discuss pending security vulnerabilities not patched here, stating: "For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available."

Bluetooth
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3753. By sending maliciously crafted Service Discovery Protocol (SDP) packets to an iPhone with Bluetooth enabled, an attacker within range may be able to trigger the issue, which may in turn lead to unexpected application termination or arbitrary code execution. Apple credits Kevin Mahaffey and John Hering of Flexilis Mobile Security for reporting this vulnerability.

Mail man-in-the-middle attack
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3754. When Mail is configured to use SSL for incoming and outgoing connections, it does not warn the user when the identity of the mail server has changed or cannot be trusted and could lead to a man-in-the-middle attack.

Mail telephone link
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3755. "By enticing a user to follow a telephone link in a mail message, an attacker can cause iPhone to place a call without user confirmation." Apple credits Andi Baritchi of McAfee for reporting this vulnerability.

Safari 1
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3756. "A design issue in Safari allows a Web page to read the URL that is currently being viewed in its parent window. By enticing a user to visit a maliciously crafted Web page, an attacker may be able to obtain the URL of an unrelated page." Apple credits Michal Zalewski of Google and Secunia Research for reporting this issue.

Safari 2
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3757. "Safari supports telephone ("tel:") links to dial phone numbers. When a telephone link is selected, Safari will confirm that the number should be dialled. A maliciously crafted telephone link may cause a different number to be displayed during confirmation than the one actually dialled. Exiting Safari during the confirmation process may result in unintentional confirmation." Apple credits Billy Hoffman and Bryan Sullivan of HP Security Labs, formerly SPI Labs, and Eduardo Tang for reporting this issue.

Safari 3
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3758. "A cross-site scripting vulnerability exists in Safari that allows malicious Web sites to set JavaScript window properties of Web sites served from a different domain. By enticing a user to visit a maliciously crafted Web site, an attacker can trigger the issue, resulting in getting or setting the window status and location of pages served from other Web sites." Apple credits Michal Zalewski of Google for reporting this issue.

Safari 4
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3759. "Safari can be configured to enable or disable JavaScript. This preference does not take effect until the next time Safari is restarted. This usually occurs when the iPhone is restarted. This may mislead users into believing that JavaScript is disabled when it is not."

Safari 5
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3760. "A cross-site scripting issue in Safari allows a maliciously crafted Web site to bypass the same-origin policy using 'frame' tags. By enticing a user to visit a maliciously crafted Web page, an attacker can trigger the issue, which may lead to the execution of JavaScript in the context of another site." Apple credits Michal Zalewski of Google and Secunia Research for reporting this issue.

Safari 6
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-3761. "A cross-site scripting issue in Safari allows JavaScript events to be associated with the wrong frame. By enticing a user to visit a maliciously crafted Web page, an attacker may cause the execution of JavaScript in the context of another site."

Safari 7
This patch affects users of Apple iPhone and addresses the vulnerability in CVE-2007-4671. "An issue in Safari allows content served over HTTP to alter or access content served over HTTPS in the same domain. By enticing a user to visit a maliciously crafted Web page, an attacker may cause the execution of JavaScript in the context of HTTPS Web pages in that domain." Apple credits Keigo Yamazaki of Little Earth Corporation for reporting this issue.

Robert Vamosi reported from San Francisco for CNET News.com.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Windows Phone: Photography the key to its success? http://t.co/14swIy1J

National Botnet Network coming: Earthwave http://t.co/BsCUwtGW via @zdnetaustralia

Windows Phone: Photography the key to its success? http://t.co/CBVdS9f7

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

Windows Phone: Photography the key to its success?: I tend to do a bit of digital photography when I go on trips... http://t.co/lAYofzgi

CASE STUDY: using #msdyncrm to cope with growing number of client comms http://t.co/qA1SxZLO #personalinjury #legaluk #solicitors #lawyers

Windows Phone: Photography the key to its success? - ZDNet (blog): ZDNet (blog)Windows Phone: Photography the ke... http://t.co/HPArdCe0

One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/F8nJ7xK6

“@ZDNet: One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/oAE1ifmp”....a DR solution, that is for the little guys.

TechnologyOne keeps profits growing: http://t.co/A7J5uDlT

“@btviewpoint: #Cybercrime golden age over in two years? - #Security - #News - http://t.co/ZEmny2dI

“@ZDNet: Can Windows 8 tablet be priced low enough to compete with iPad, Kindle Fire? http://t.co/b7n4Wb7C” .....unlikely, and disappointing

#Cybercrime golden age over in two years? - #Security - #News - http://t.co/Mvc37WAr

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

United States, Australia team up on cybersecurity http://t.co/41IYTcDx

$50m to Medicare locals for eHealth http://t.co/VM5ts5lf

RT @adrianbritton: Goodbye Friending #Facebook: We only part to meet again http://t.co/gXZEKtEE #socialmedia

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

Microsoft admits Vista was 'cheesy' http://t.co/Yd6fSLyx

We Are Specialty Supply Miu Miu Handbags, Miu Miu Pocketbook, Miu Miu Sunglasses And So On. Miu Miu Car-boot sale Online Strapping Reduct...

3 hours ago by ExedegamEmodo on Reservoir blogs: Fan fakes Tarantino diary

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

3 hours ago by forporoExpoxy on Reservoir blogs: Fan fakes Tarantino diary

Goods Shopping Location Diminish Of Japan's Largest Overseas Train Brands. Coach Outlet Recover 89% Off.We Entertain Stuffed Items Such A...

3 hours ago by MentIdott on Reservoir blogs: Fan fakes Tarantino diary

Our Stow away Tender Exercise Bags Of The Cheapest Quotation, 50-75% OFF. Secured Shipping To Japan. Detailed Inferior Instructor Handbag...

3 hours ago by Hieffiftsoinc on Reservoir blogs: Fan fakes Tarantino diary

http://t.co/gNQkl0gd

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機...

3 hours ago by Scafthapthinc on Reservoir blogs: Fan fakes Tarantino diary

3 hours ago by antaftilk on Reservoir blogs: Fan fakes Tarantino diary

Our Aggregate Wholesale Trainer Bags Of The Cheapest Consequence, 50-75% OFF. Self-indulgent Shipping To Japan. Exquisite Worthless Drill...

4 hours ago by meltygypent on Reservoir blogs: Fan fakes Tarantino diary

Celine belongings,Celine case,purse Celine,CELINE Celine is synonymous with je sais quoi and faultlessness prevalent since founding in 19...

4 hours ago by dendyBymNTedo on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung http://t.co/95pDxClp

4 hours ago by Fedaupdat on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung - ZDNet (blog): Global mobile phone sales t... http://t.co/GtLqWFz1

ABC's Bitcoin miner tackled in minutes: The Australian Broadcasting Corporation (ABC) looked set to become a hav... http://t.co/qq5oPZ15

ABC's Bitcoin miner tackled in minutes: The Australian Broadcasting Corporation (ABC) looked set to become a hav... http://t.co/7v06Ygfl

ABC's Bitcoin miner tackled in minutes: The Australian Broadcasting Corporation (ABC) looked set to become a hav... http://t.co/z7ngF4XL

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

5 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Oracle v. Google loses another juror: By Rachel King, ZDNet US on May 21st, 2012 (7 hours ago) Rather than 12 An... http://t.co/nflnWgb9

RT @MSDynamicsCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/LKjZzQcR #msdyncrm #crm2011 ^pb

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

5 hours ago by brozza on Broadband Speedtest

Vic councils tender for VMware partner http://t.co/diHsmLt6

Govt set for electorate office IT refresh: The Department of Parliamentary Services (DPS) is waiting for existin... http://t.co/FYaojbCN

RT @zdnetaustralia: In this week's Patch Monday we look at the themes of last week's AusCERT security conference. http://t.co/XMRm8n9k ^ST

Facebook tracking you after you logout, isn't that against the law? To stop this, go to the settings / options /... http://t.co/6Gzl4Eht

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

7 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

9 hours ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

9 hours ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

10 hours ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

10 hours ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

10 hours ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

11 hours ago by fibretech on National Botnet Network coming: Earthwave

And again - missed this bit did you? "... Telstra is responsible for estates where development approval was granted before 1 January 201...

11 hours ago by Beta on Copper greenfield dominance irrelevant: Conroy

I think the idea of dropping aero glass bit of a mistake. At least have some colour. Thats something i liked (especially after working on...

11 hours ago by JCOZ on Microsoft admits Vista was 'cheesy'

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar