CVE-2011-0154

WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:23

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html - Vendor Advisory, Mailing List () http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html - Mailing List, Vendor Advisory
References () http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html - Vendor Advisory, Mailing List () http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html - Mailing List, Vendor Advisory
References () http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html - Patch, Vendor Advisory, Mailing List () http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html - Mailing List, Patch, Vendor Advisory
References () http://support.apple.com/kb/HT4554 - Vendor Advisory () http://support.apple.com/kb/HT4554 - Vendor Advisory
References () http://support.apple.com/kb/HT4564 - Vendor Advisory () http://support.apple.com/kb/HT4564 - Vendor Advisory
References () http://support.apple.com/kb/HT4566 - Vendor Advisory, Broken Link () http://support.apple.com/kb/HT4566 - Broken Link, Vendor Advisory
References () http://www.zerodayinitiative.com/advisories/ZDI-11-101 - Third Party Advisory, VDB Entry () http://www.zerodayinitiative.com/advisories/ZDI-11-101 - Third Party Advisory, VDB Entry
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17308 - Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17308 - Third Party Advisory

Information

Published : 2011-03-03 20:00

Updated : 2024-11-21 01:23


NVD link : CVE-2011-0154

Mitre link : CVE-2011-0154

CVE.ORG link : CVE-2011-0154


JSON object : View

Products Affected

apple

  • iphone_os
  • itunes

microsoft

  • windows
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer