MEDIUM · 4.3

CVE-2008-1589

Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which make...

Vulnerability Description

Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
AppleIphone1.0
AppleIpod Touch1.1
AppleIphone Os1.0.1
AppleSafariAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-1589?

CVE-2008-1589 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which make...

How severe is CVE-2008-1589?

CVE-2008-1589 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1589?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Iphone, Apple Ipod Touch, Apple Iphone Os, Apple Safari.