Sunday, October 7, 2007

Old TIFF Vuln on New iPhone

Via Macnn.com (Oct 4th) -

A newly discovered iPhone exploit could help developers find another way to run third-party applications on Apple's device. Posters to the Hackintosh forums have discovered that Mobile Safari on both the Touch and the iPhone suffer from a one year old TIFF buffer overflow exploit that could lead to a jailbreak for the devices. Essentially, opening a carefully crafted TIFF image will crash Mobile Safari, causing a buffer overflow and allow for arbitrary code execution. A poster to the forums writes "This same exploit was used more than 1.5 years ago to crack the PSP firmware." This could theoretically lead to a new "jailbreak" process that would again allow third-party applications to be written to iPhones running the most recent firmware 1.1.1 release that disabled the functionality for all those who updated.

------------------------

Surprise, Surprise! Forget me if this is old news, I have been out of town most of the weekend.

No comments:

Post a Comment