CVE-2011-0154
Apple iPhone Webkit Library Javascript Array sort Method Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
WebKit, tal como se utiliza en el iTunes de Apple antes de v10.2 para Windows y Apple OS, no implementa correctamente la función .sort para matrices de JavaScript, lo que permite a los atacantes "man-in-the-middle" ejecutar código de su elección o causar una denegación de servicio (corrupción de memoria y bloqueo de la aplicación)a través de vectores relacionados con la navegación de la tienda iTunes, una vulnerabilidad diferente a los CVE listados en APPLE-SA-2011-03-02-1.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple's iPhone Webkit library. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the way the library implements the .sort function for an array. The library will trust the implementation of a particular method which when executed can be used to manipulate elements out from underneath it. This can lead to code execution under the context of the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-12-23 CVE Reserved
- 2011-03-02 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-11-101 | Third Party Advisory |
|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17308 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html | 2021-06-23 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html | 2021-06-23 | |
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html | 2021-06-23 | |
http://support.apple.com/kb/HT4554 | 2021-06-23 | |
http://support.apple.com/kb/HT4564 | 2021-06-23 | |
http://support.apple.com/kb/HT4566 | 2021-06-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 10.2 Search vendor "Apple" for product "Itunes" and version " < 10.2" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | - | - |
Safe
|
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 10.2 Search vendor "Apple" for product "Itunes" and version " < 10.2" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|