July 11, 2008 10:57 AM PDT

iPhone and iPod Touch updated with security patches

Updated 12:05 p.m. PDT Friday to correct where the update is available. It is available through iTunes.

On Friday, Apple released iPhone 2.0 and iPod Touch 2.0 firmware that includes several security fixes for Safari and WebKit. Several of the Safari fixes have been previously issued for Mac OS X and Windows. The update, APPLE-SA-2008-07-11, is only available through iTunes.

This update will not appear in your computer's Software Update application or on the Apple Downloads site. The patches may take up to one week to be detected, depending on the day a device checks. A manual update can be accomplished by using the "Check for Update" button within iTunes.

CFNetwork
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses CVE-2008-0050, a spoofing vulnerability. Apple says " A malicious HTTPS proxy server may return arbitrary data to CFNetwork in a 502 Bad Gateway error, which could allow a secure website to be spoofed. This update addresses the issue by not returning the proxy-supplied data on an error condition."

Kernel
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-0177. Apple explains: "An undetected failure condition exists in the handling of packets with an IPComp header. Sending a maliciously crafted packet to a system configured to use IPSec or IPv6 may cause an unexpected device reset. This update addresses the issue by properly detecting the failure condition."

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-1588. Apple explains: "When Safari displays the current URL in the address bar, Unicode ideographic spaces are rendered. This allows a maliciously crafted website to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by not rendering Unicode ideographic spaces in the address bar."

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability within CVE-2008-1589. Apple says " When Safari accesses a website that uses a self-signed or invalid certificate, it prompts the user to accept or reject the certificate. If the user presses the menu button while at the prompt, then on the next visit to the site, the certificate is accepted with no prompt. This may lead to the disclosure of sensitive information." Apple credits Hiromitsu Takagi with reporting this vulnerability.

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the arbitrary code execution vulnerability within CVE-2008-2303. Apple explains "A signedness issue in Safari's handling of JavaScript array indices may result in an out-of-bounds memory access. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript array indices." Apple credits SkyLined of Google for reporting the vulnerability.

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the cross-site scripting vulnerability details within CVE-2006-2783. Apple explains "Safari ignores Unicode byte order mark sequences when parsing web pages. Certain websites and web content filters attempt to sanitize input by blocking specific HTML tags. This approach to filtering may be bypassed and lead to cross-site scripting when encountering maliciously-crafted HTML tags containing byte order mark sequences. This update addresses the issue through improved handling of byte order mark sequences." Apple credits Chris Weber of Casaba Security for reporting the vulnerability.

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-2307. Apple says "A memory corruption issue exists in WebKit's handling of JavaScript arrays. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution." Apple credits James Urquhart for reporting the vulnerability.

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-2317. Apple explains "A memory corruption issue exists in WebCore's handling of style sheet elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved garbage collection." Apple credits Peter Vreudegnhil working with the TippingPoint Zero Day Initiative for reporting the vulnerability.

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2007-6284. Apple says "A memory consumption issue exists in the handling of XML documents containing invalid UTF-8 sequences, which may lead to a denial of service."

Safari
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-1767. Apple says "A memory corruption issue exists in the libxslt library. Viewing a maliciously crafted HTML page may lead to an unexpected application termination or arbitrary code execution." Apple credits Anthony de Almeida Lopes of Outpost24 AB, and Chris Evans of Google Security Team for reporting the vulnerability.

WebKit
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-1590. Apple says "A memory corruption issue exists in JavaScriptCore's handling of runtime garbage collection. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution." Apple credits Itzik Kotler and Jonathan Rom of Radware for reporting the vulnerability.

WebKit
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-1025. Apple says "An issue exists in WebKit's handling of URLs containing a colon character in the host name. Accessing a maliciously crafted URL may lead to a cross-site scripting attack. This update addresses the issue through improved handling of URLs." Apple credits Robert Swiecki of the Google Security Team, and David Bloom for reporting the vulnerability.

WebKit
This patch affects users of iPhone v1.0 through v1.1.4, and iPod Touch v1.1 through v1.1.4. The update addresses the vulnerability detailed within CVE-2008-1026. Apple says "A heap buffer overflow exists in WebKit's handling of JavaScript regular expressions. The issue may be triggered via JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution." Apple credits Charlie Miller of Independent Security Evaluators for reporting the vulnerability.

Recent posts from News - Security
Microsoft: Expect four bulletins on Patch Tuesday
Protesters decry NASA hacker's extradition
Chrome suffers first security flaw
Microsoft proposes age-limited digital playgrounds
Microsoft slams Google on privacy
Add a Comment (Log in or register) 2 comments
by ballmerisanape July 11, 2008 11:41 AM PDT
Cool... now if the IT guy that accidently tripped over the power supply cord in Apple's server room would turn back and plug that baby back in.. I might be able to update my Touch..
Reply to this comment
by Karl Viklund July 15, 2008 9:30 AM PDT
Very good very good.
Lets just hope the can be faster with patches in the future for the iPhone.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

About News - Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

News - Security topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Timing rumors surface for AMD plant spin-off

    Rumors persist that Advanced Micro Devices is planning to spin off all or part of its manufacturing operations.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Digital Noise: Music and Tech

    Was 1980s music that bad?

    NPR asks listeners which year featured the best music, and the 1980s emerge as a bleak era. Personally, the '80s figure prominently in my collection, but well behind the 1970s.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    Michael Moore plans Net-only film premiere

    Filmmaker plans to premiere his latest documentary exclusively on the Internet for free, forgoing the traditional theatrical release.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    What you can--and can't--find about Palin on the Internet

    John McCain's choice of Sarah Palin as a running mate has inspired a wealth of creativity on the Internet.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Crossfade

    Ying Yang Twins, 'Look Back At It': Free MP3 of the Day

    This amped-up duo gets the party started with a mix of crisp, Southern hip-hop beats and shout-along rhymes. Download a free MP3 of "Look Back At It" courtesy of CNET Download Music.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.