Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple > Iworld > iPhone

February 3rd, 2010, 13:53 GMT · By

The Security Content of iPhone OS 3.1.3

SHARE:

Adjust text size:


Apple Support document header
Enlarge picture
Besides improving the accuracy of reported battery level on iPhone 3GS, and resolving an issue where third-party apps would not launch, Apple has included security fixes in its latest iPhone OS update, further enhancing the reliability of the operating system.

iPhone OS 3.1.3 is available today for both iPhone and iPod touch owners. The new firmware arrived alongside an updated SDK for developers, and one day after iTunes 9.0.3 was released. It addresses a few minor issues (except, perhaps, for the battery life problems plaguing 3GS users), but also a handful of serious security holes that could be exploited by hackers.

Via the Support section of its website, the Mac maker reveals that a buffer overflow exists in the handling of mp4 audio files, while playing such a maliciously crafted mp4 audio file would lead to an unexpected application termination or arbitrary code execution. Addressed through improved bounds checking, the issue is gone in firmware 3.1.3, thanks to research done by Tobias Klein of trapkit.de, who reported the issue to Apple.

An additional four vulnerabilities are detailed in the respective technote, including one where memory corruption in the handling of a certain USB control message would allow a person with physical access to the device to use this to bypass the passcode and access the user's data. Addressed through improved handling of the USB control message, this hole is also now plugged in every device model.

Other issues addressed include:

 - accessing a maliciously crafted FTP server resulting in an unexpected application termination, information disclosure, or arbitrary code execution;
 - mail may load remote audio and video content when remote image loading is disabled;
 - viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.

Download iPhone OS / Firmware Update (Free)

TELL US WHAT YOU THINK:

1,789 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Leaked Picture of iPhone 4 Emerges (Unconfirmed)

iPhone / iPod touch 3.1.3 IPSW Download Sources

Dev Team Confirms iPhone 3.1.3 IPSW Jailbreak

Developers Get iPhone SDK 3.1.3

iPhone OS 3.1.3 Now Available

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM