Wednesday December 3, 2008 1:34 AM AEST
Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Apple fixes 10 iPhone bugs

  • Email a Friend
  • Print Page
Apple fixes 10 iPhone bugs
Seven fixes affected Safari browser vulnerabilities. Of the remaining three Bluetooth-related updates, one fixed a "critical" flaw that could allow outsiders to eavesdrop on iPhone conversations.

Of the common vulnerability enumerations, Apple's term for patches, Andrew Storms, director of network security for nCircle, said: "The Bluetooth bug is the most critical."

Apple added that an attacker could send maliciously crafted service discovery protocol packets to an iPhone with Bluetooth enabled to run malicious code for intercepting the wireless conversation.

"Even though this is labelled as a remote exploit, due to the nature of Bluetooth, this is more of a walk-by attack than a drive-by attack," Storms said via email. "The hacker would have to be within arm's length to exploit it."

Apple also closed a man-in-the-middle flaw in iPhone that impacts its mail capabilities when configured to use the secure socket layer protocol. In this situation, an unpatched iPhone "does not warn the user when the identity of the mail server has changed or cannot be trusted and could lead to a man-in-the-middle attack," according to Apple.

Thursday's round of Apple patches also resolved a number of problems within the iPhone's Safari browser. One of them fixed a cross-site scripting vulnerability that allows malicious websites to run unauthorised JavaScript code.

According to researchers at Lumension (formerly PatchLink), Apple's updates have the potential to cause irreparable damage to iPhones that installed so-called "unlock code.” It is most often used to allow the iPhone to connect with a cellular service other than AT&T.

Damien Hogan, security analyst at Lumension, said that the vulnerabilities could be exploited to download the unlock code on to an unsuspecting user's iPhone. Such unauthorised modifications could not only make the phone unusable, they would also void Apple's warranty, he said.


Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers