iPhone OS 3.0.1 security update out, fixes SMS security vulnerability issue

Posted Jul 31, 2009 at 2:13PM by Karl B. Listed in: News Tags: Berlin, Hackers, Independent Security Evaluators, iPhone, SMS, Technical University
Ó


iPhone security update 3.0.1 - Image 1


A flaw that could open up every iPhone in the world to attack was made public by a pair of hackers earlier this week. Now Apple has moved to patch the hole in the iPhone's security.

Security update 3.0.1 has been rolled out to fix the SMS security vulnerability. It's available now for all iPhone models and OS versions. Apple is advising everyone who own as iPhone to update their devices. Of course, as with every official update, this could adversely affect homebrew apps.

Here's a description from the Apple Support page:

A memory corruption issue exists in the decoding of SMS messages. Receiving a maliciously crafted SMS message may lead to an unexpected service interruption or arbitrary code execution. This update addresses the issue through improved error handling. Credit to Charlie Miller of Independent Security Evaluators, and Collin Mulliner of Technical University Berlin for reporting this issue.




Related articles:


Via Apple Support

 
 
 

Comments [refresh]

by TheRockness - 2009-07-31 09:44
» That was fast.

They've known about it for a month, but as soon as it went public, it was fixed pretty quick. Good on ya Apple.

by ilostchild - 2009-07-31 15:18
» stupidity what it is

Apple is stupid.. cause it went public and its been up for so long they didnt care to patch it... till someone publicly said its there... now apple had to cover up their dirty tracks..

by TheRockness - 2009-07-31 15:40
» I'm not sure I follow.

It went public, and then it went public again?



I think I see what you're trying to say. I'll give you a break since its friday night and we all should be making mistakes by now. I'll blow a smoke ring for you.

by HIMFan - 2009-08-01 06:11
» Well.

For those who have 3.0 Jailbroken, you can download the update and use the SAME exact jailbreaking method on 3.0.1, and it works.

by salvator - 2009-08-01 20:57
» Limitations of 3GS,3G,2G Apple phones

For every firmware update or restore even on 3.01,it removes all 3rd party apps installed thru' Cydia except those purchased.U need backup those using apps in Cydia.



Another issue with Apple is that the base size for 3G,3GS new 3.0 firmware onwards is 500megs. Old Iphone is 300megs. Most programs install a bit onto the main memory space and the rest on the gigs depending on the size that you bought.Upon installing apps to 11 homescreens,u will realized the apps start disappearing even though you did install it and it still resides in the phone thru' the search options.



Apple developers do not honor even those good programmers who do not resides in their commercial scheme store. Their reason is that they fear those apps will damage the system structure of the phone.



This has been realized and it is the truth.The appropriate team are not aware until more people points the problem to them. Or they have assume most won't install that much applications and insists there wasn't any problems. It is only a matter of time and space. It will come.

by MyOWn - 2009-08-02 01:45
» No

3.0.1 is still hackable via SMS!

Add comment

Security code
Refresh

Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!