The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not properly limit the dialing methods, which allows physically proximate attackers to bypass intended access restrictions and make FaceTime calls through Voice Dialing, or obtain sensitive contact information by attempting to make a FaceTime call and reading the contact suggestions.
References
Link | Resource |
---|---|
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html | Vendor Advisory |
http://osvdb.org/85620 | |
http://support.apple.com/kb/HT5503 | Vendor Advisory |
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html | Vendor Advisory |
http://osvdb.org/85620 | |
http://support.apple.com/kb/HT5503 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html - Vendor Advisory | |
References | () http://osvdb.org/85620 - | |
References | () http://support.apple.com/kb/HT5503 - Vendor Advisory |
Information
Published : 2012-09-20 21:55
Updated : 2024-11-21 01:41
NVD link : CVE-2012-3738
Mitre link : CVE-2012-3738
CVE.ORG link : CVE-2012-3738
JSON object : View
Products Affected
apple
- iphone_os
CWE
CWE-264
Permissions, Privileges, and Access Controls