Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Apple > Iworld

August 12th, 2010, 06:26 GMT · By

iOS 4.0.2 Released for iPhone, iPod touch

SHARE:

Adjust text size:


Apple shows availability of iOS 4.0.2 software update
Enlarge picture
As promised, Apple has released a new incremental update for customers using iOS devices to patch a vulnerability that could allow arbitrary code execution for gaining system privileges. iOS 4.0.2 is a free software update for all supported iPhone, iPod touch models.

A note on the Support section of Apple’s web site reveals that iOS 4.0.2 “fixes security vulnerability associated with viewing malicious PDF files.” The vulnerability is known to have allowed hackers to create an untethered jailbreak tool for iOS devices.

According to Apple, products compatible with this software update are the iPhone 3G, iPhone 3GS, iPhone 4, iPod touch 2nd generation and  iPod touch 3rd generation (late 2009 models
with 32GB or 64GB).

As explained by F-Secure in a post on the security issues surrounding iOS 4, it was actually two vulnerabilities that the jailbreakme.com hack leveraged to compromise iOS devices.

“First one uses a corrupted font embedded in a PDF file to execute code and the second one uses a vulnerability in the kernel to escalate the code execution to unsandboxed root,” Mikko, of F-Secure wrote.

Also, according to Apple, the issue has been present in the iPhone operating system since version 2.0.

A Support document on Apple’s web site now acknowledges the two holes which, according to the iPhone maker, have been plugged as of iOS 4.0.2.

Available for: iOS 2.0 through 4.0.1 for iPhone 3G and later, iOS 2.1 through 4.0 for iPod touch (2nd generation) and later, “A stack buffer overflow exists in FreeType's handling of CFF opcodes,” the company explains.

“Viewing a PDF document with maliciously crafted embedded fonts may allow arbitrary code execution,” the Cupertino-based company reveals. “This issue is addressed through improved bounds checking.”

“An integer overflow exists in the handling of IOSurface properties, which may allow malicious code running as the user to gain system privileges,” Apple adds, referring to the second hole that iOS 4.0.2 plugs. “This issue is addressed through improved bounds checking,” the company concludes.

Owners of a supported iPhone or iPod touch may update to the new iOS version by connecting their device to a computer with iTunes installed. The software will notify them of the new software version, at which point the user can choose to download and install the update automatically.

Alternately, users may download the iOS 4.0.2 IPSW file manually (download link below) and selectively restore to the new firmware with iTunes, using the Alt (Option) key.

Download iOS Software Update for iPhone, iPod touch (Free)

TELL US WHAT YOU THINK:

3,700 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Fotopedia Heritage Puts 20,000 Amazing Pictures on Your iOS Device

Find and Share the Hottest Deals with Dealmap for iPhone

Teardown Provides Evidence of 3-Axis Gyro in Next-Gen iPad

Apple Admits to Overheating iPods

Gruber: New iPod touch Ships Next Week with Retina Display, Dual Cameras

READER COMMENTS:


Comment #1 by: Jack on 12 Aug 2010, 07:44 UTC reply to this comment

Apple's ios 4.0.2 is useless for some iphone owners cos it contributes nothing beside fixing its own ios defect. In fact, jailbreak iphone 3g, at least allow iphone owners use some features: backgrounding, multitasking, some apps which are not approved by Apple. Apple should open eye at Nokia, although old version like N70, it allows user use multi-tasking, view pdf file, run flash player.


Comment #2 by: Hellteaser2121 on 24 Nov 2010, 19:02 UTC reply to this comment

I just updated the software of my ipod touch to 4.0.2, and, for me, I can't see any changes on my unit, I cant tell whether the performance of my unit just improve or not, or even get worse


Comment #3 by: Yall on 31 Mar 2011, 09:19 UTC reply to this comment

ios 4.3.1 is available now and 4media ipad max compatible with new ios 4.3.1 to recognize my ipad os

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM