CVE-2008-2303

Properties

Published:
13.07.2008
Updated:
15.07.2008
Patch available:
Severity:
High
CVSS vector:
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Product:
Apple: Safari

Vulnerability description

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

References:

APPLE: http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
BID: http://www.securityfocus.com/bid/30186