Home > Security News > Apple iPhone 2.2 update includes critical security patches
Security News:
EMAIL THIS

Apple iPhone 2.2 update includes critical security patches

By SearchSecurity.com Staff
21 Nov 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Apple issued version 2.2 of its iPhone firmware, repairing at least a dozen security issues, including dangerous flaws in its Safari browser that attackers can exploit to steal passwords, account information and other sensitive data.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

Version 2.2 of the firmware addresses software flaws in both the iPhone and iPod touch. Several issues address problems with the way Safari handles HTML table and iframe elements. An attacker could exploit the flaws to cause a memory corruption and execute arbitrary code, Apple said in its advisory. One of the errors enables an attacker to spoof the user interface, Apple said.

A TIFF image handling error can be exploited by an attacker by tricking the user to view a malicious TIFF image. CoreGraphics contains memory corruption issues resulting in processing errors. An attacker can exploit the issues to pass arbitrary code or conduct a denial-of-service (DDoS) attack Some TIFF imaging errors cause the device to reset, Apple said.

A networking error was also corrected. An error with the default setting reduced the encryption level for point-to-point tunneling protocol (PPTP) and virtual private network (VPN) connections.
SearchSecurity radio:

A flaw in Office Viewer could also be exploited by an attacker by tricking a user into viewing a malicious Microsoft Excel file. "Viewing a maliciously crafted Microsoft Excel file may lead to an unexpected application termination or arbitrary code execution," Apple said.

Several passcode and SMS messaging errors were also addressed, Apple said. The software maker also addressed a bug that allowed a user to dial non-emergency numbers when locked out of the iPhone.

Danish vulnerability clearinghouse Secunia gave the flaws a highly critical rating. It said the flaws "can be exploited by malicious people to bypass certain security restrictions, disclose potential sensitive information, conduct spoofing attacks … or potentially compromise a user's system."

Tags: Handheld and Mobile Device Security Best PracticesWeb Browser SecuritySmartphone and PDA Viruses and ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Handheld and Mobile Device Security Best Practices
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
How secure are iPhone App Store mobile applications?
Is there a spy on my mobile device?
Mobile phones win during Pwn2Own contest
Latest Apple iPhone features prompt security concerns
Apple iPhone app could boost two-factor
What Obama's Blackberry means for mobile device security
SMS mobile worm attacks Symbian smartphones
Smartphone security lacking at many businesses
Handheld and Mobile Device Security Best Practices Research

Web Browser Security
Security researchers develop browser-based darknet
Microsoft cracks down on click fraud ring
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
IT pros can detect, prevent website vulnerabilities, thwart attacks
Stolen FTP credentials likely in massive website attacks
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
Google study backs browser silent auto update feature
Firefox update addresses several security flaws
Web Browser Security Research

Smartphone and PDA Viruses and Threats
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
Latest Apple iPhone features prompt security concerns
SMS mobile worm attacks Symbian smartphones
Smartphone security lacking at many businesses
RIM warns of serious vulnerability in BlackBerry Web loader
RIM fixes serious BlackBerry PDF handling flaws
How easily can spyware be placed on a mobile phone?
Should enterprises ban USBs because the DoD banned them?
RIM updates BlackBerry Desktop Software to fix ActiveX flaw

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
browser hijacker  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
honey monkey  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
NCSA  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts