MEDIUM · 6.9

CVE-2010-2973

Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as...

Vulnerability Description

Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AppleIphone Os4.0
AppleIpadAll versions
AppleIpod TouchAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2973?

CVE-2010-2973 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as...

How severe is CVE-2010-2973?

CVE-2010-2973 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2973?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Iphone Os, Apple Ipad, Apple Ipod Touch.