iPhone Forum  

Go Back   iPhone Forum > iPhone Forums > iPhone Chat

AddThis Social Bookmark Button
Home Register iPhone FAQ iPhone Wallpapers FAQ Search Today's Posts Mark Forums Read


Talk iPhone - iPhone Forum

Welcome to the iPhone Forums, Here you'll find the latest iPhone news, articles and discussion for the Apple iPhone. With discussion forums and helpcovering iphone unlocking, jailbreaking and all types of iPhone applications.

Registration is fast, simple and absolutely free so please, Join Our Community Today!

Reply
 
Thread Tools Display Modes
Old 08-01-2007   #1
Member
 
launchpad's Avatar
 
Join Date: Jul 2007
Posts: 35
launchpad is on a distinguished road
Apple just released an update to the iPhone "version 1.0.1." There is no word about what changed, but it is reported to cover MANY “bug fixes. So go and get your update...
launchpad is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-01-2007   #2
Senior Member
 
Kender's Avatar
 
Join Date: May 2007
Location: Grand Rapids, MI
Posts: 262
Kender is on a distinguished road
Phone v1.0.1 Update

Safari

CVE-ID: CVE-2007-2400

Available for: iPhone v1.0

Impact: Visiting a malicious website may allow cross-site scripting

Description: Safari's security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, and Ed Rowe of Adobe Systems, Inc. for reporting this issue.

Safari

CVE-ID: CVE-2007-3944

Available for: iPhone v1.0

Impact: Viewing a maliciously crafted web page may lead to arbitrary code execution

Description: Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues.

WebCore

CVE-ID: CVE-2007-2401

Available for: iPhone v1.0

Impact: Visiting a malicious website may allow cross-site requests

Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could trigger a cross-site scripting issue. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

WebKit

CVE-ID: CVE-2007-3742

Available for: iPhone v1.0

Impact: Look-alike characters in a URL could be used to masquerade a website

Description: The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check.

WebKit

CVE-ID: CVE-2007-2399

Available for: iPhone v1.0

Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.
__________________
Signature for rent! Please ask me how!
Kender is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-01-2007   #3
Member
 
Join Date: Jul 2007
Location: Central PA
Posts: 72
SimonTuffGuy is on a distinguished road
Sweet! Downloading now.
SimonTuffGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-01-2007   #4
Member
 
Join Date: Jul 2007
Location: Central PA
Posts: 72
SimonTuffGuy is on a distinguished road
I read that people we're having problems if they've hacked their phone (iFuntastic? Not sure if that's just come ringtones or what)...

I'm happy to report that everything is functioning correctly on mine, even the ringtones that I loaded with the iPhoneRingToneMaker program...
SimonTuffGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-03-2007   #5
Member
 
Join Date: Jul 2007
Posts: 35
iLoveIt is on a distinguished road
I can't wait for them to release an update so you can download iTunes songs from iPhone and then use them as ringtones.

Haven't noticed a difference with 1.0.1 but I hope it's more secure.
iLoveIt is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-03-2007   #6
Member
 
Join Date: Jul 2007
Location: Central PA
Posts: 72
SimonTuffGuy is on a distinguished road
iLoveIt - You Windows or Mac? Get the iPhoneRingtoneMaker that's posted on the site here... It cost me $10, but I can put unlimited ringtones on the phone and I had no problems updating it.

When Apple released their new iTunes update, you're going to get charged the regular fee to convert to a ringtone (I think it's $1)...
SimonTuffGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-04-2007   #7
Member
 
Join Date: Jul 2007
Posts: 35
iLoveIt is on a distinguished road
I'm a mac but ten bucks is more just for a few, plus I hate third part software. I like things to mesh seemlessly.

Last edited by iLoveIt : 08-10-2007 at 03:34 AM.
iLoveIt is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Old 08-06-2007   #8
Member
 
Join Date: Jul 2007
Location: Central PA
Posts: 72
SimonTuffGuy is on a distinguished road
Quote:
Originally Posted by iLoveIt View Post
I'm a mac but ten bucks is more just for a few, plus u hate third part software. I like things to mesh seemlessly.
Eh - I'd hold off for Apple to release their iTunes update then that'll add new ringtones.

I thought when I saw the iTunes updated download to my PC on Friday that it would have that added in. Just looked to be some bug fixes.

While it doesn't mesh seemlessly, it does work and that's what I find important. It'll be interesting to see how it works when iTunes is ringtone-ready (will mine already display there, will iTunes pull them off the phone?)... Hmmm

I figured, $10 is 10 ringtones from Apple (plus waiting until they are ready to release their upgrade)... I shared it with my brother and we each loaded at least 5 ringtones to our phones. That pays for itself... If it doesn't work with iTunes when the new version is released, I'm sure an update will come out for it.

*shrug*

I just know that I'm enjoying my own custom ringtones without any problems from update 1.0.1... (while I saw reviews from people who did the jailbreak stuff or other hacked methods of getting ringtones who had to restore their phone before they could upgrade)...
SimonTuffGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiStumble this Post!
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
AT&T Suggest iChat Update? iAm Latest iPhone News 8 01-01-2008 08:17 PM
iPhone Update: Youtube officially announced! Kender iPhone Chat 0 06-20-2007 02:06 PM
Apple update iPhone website with new 3D previews Tanker iPhone Chat 0 06-18-2007 12:04 PM


Network: Android Forums - Talk Android Community



Apple | iPhone Accessories | iPhone Applications | iPhone Articles | iPhone Features | iPhone Games | iPhone Hacking | iPhone Hardware | iPhone News | iPhone Rumors | iPhone Security | iPhone Software | iPhone Stuff

Copyright (c) 2007 TalkiPhone.com. All rights reserved. All trademarks and copyrights remain the property of their respective owners.
vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.