Subscribe via feed.

My Photo Wifi Share & PS 1.1 Command Injection

Posted by deepcore under Apple (No Respond)

My Photo Wifi Share & PS 1.1 for iOS suffers from a local command injection vulnerability.

Tags: , ,

Easy FileManager 1.1 Local File Inclusion / Shell Upload

Posted by deepcore under Apple (No Respond)

Easy FileManager version 1.1 for iOS suffers from local file inclusion and remote shell upload vulnerabilities.

Tags: , ,

ePhone Disk 1.0.2 LFI / Command Injection / DoS

Posted by deepcore under Apple (No Respond)

ePhone Disk version 1.0.2 for iOS suffers from denial of service, command injection, and local file inclusion vulnerabilities.

Tags: , ,

OS X / Safari / Firefox REGEX Denial Of Service

Posted by deepcore under Apple (No Respond)

Mac OS X, Safari, Firefox and Kaspersky all suffer from a regular expression denial of service condition that was discovered long ago in regcomp().

Tags: , ,

Apple TV Touch Password Disclosure

Posted by deepcore under Apple (No Respond)

Apple TV had an issue where it was logging a user’s Apple ID and password via debug output in logs.

Tags: , ,

Apple Facetime Information Disclosure

Posted by deepcore under Apple (No Respond)

Facetime allows video calls for iOS. Facetime-Audio, added in iOS 7, allows audio only calls. The audio version uses a vulnerable URL scheme which is not used by Facetime Video. The URL Scheme used for Facetime-Audio allows a website to establish a Facetime-audio call to the attacker’s account, revealing the phone number or email address […]

Tags: , ,

Apple Security Advisory 2014-03-10-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-03-10-1 – iOS 7.1 is now available and addresses multiple security vulnerabilities.

Tags: , ,

Apple Security Advisory 2014-03-10-2

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-03-10-2 – Apple TV 6.1 is now available and addresses information disclosure, date checking failure, buffer overflow, and various other vulnerabilities.

Tags: , ,

Safari User-Assisted Download / Run Attack

Posted by deepcore under Apple (No Respond)

This Metasploit module abuses some Safari functionality to force the download of a zipped .app OSX application containing our payload. The app is then invoked using a custom URL scheme. At this point, the user is presented with Gatekeeper’s prompt: “APP_NAME” is an application downloaded from the internet. Are you sure you want to open […]

Tags: , ,

Apple Security Advisory 2014-02-25-1

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-02-25-1 – OS X Mavericks 10.9.2 and Security Update 2014-001 is now available and addresses multiple security issues including the recent SSL vulnerability.

Tags: , ,