CVE Vulnerabilities

CVE-2009-2204

Published: Aug 03, 2009 | Modified: Mar 30, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrated by Charlie Miller at SyScan 09 Singapore.

Affected Software

Name Vendor Start Version End Version
Iphone_os Apple * 3.0
Iphone_os Apple 1.0 1.0
Iphone_os Apple 1.0.0 1.0.0
Iphone_os Apple 1.0.1 1.0.1
Iphone_os Apple 1.0.2 1.0.2
Iphone_os Apple 1.1 1.1
Iphone_os Apple 1.1.0 1.1.0
Iphone_os Apple 1.1.1 1.1.1
Iphone_os Apple 1.1.2 1.1.2
Iphone_os Apple 1.1.3 1.1.3
Iphone_os Apple 1.1.4 1.1.4
Iphone_os Apple 1.1.5 1.1.5
Iphone_os Apple 2.0 2.0
Iphone_os Apple 2.0.0 2.0.0
Iphone_os Apple 2.0.1 2.0.1
Iphone_os Apple 2.0.2 2.0.2
Iphone_os Apple 2.1 2.1

References