Your best source of information and news about free iphone, cellphone and cellphone on the internet
iPhone REVIEW TOP 50 iPhone VIDEOS iPhone CARD iPhone SOFT

Update

You are currently browsing the articles from iPhone nano - Apple iPhone Articles matching the category Update.

Apple Fixes iMac Freeze, Releases OS X Updates

index_hero20071026.pngApple’s biggest embarrassment in recent months has finally been taken care of. The notorious iMac Freeze that has affected this summer’s revision is nipped in the bud with the iMac Graphics Firmware 1.0 Update.

Prior to this fix, iMac screens flickered and froze constantly. A lot of people were unhappy. Most readers now report that it’s taken care of. Problems solved.

The update caps two weeks of updates from Apple:

Via MacRumors

Written by Petemortensen on November 16th, 2007 with no comments.
Read more articles on Software and Update and bug.

iPhone Firmware v1.1.2 Out, Already Jailbroken

Apple has started pushing out the v1.1.2 firmware to existing iPhone users.  The obvious changes bring better support for international users in preparation for the European release in just a few hours.  There is also an update to the radio firmware.  This may also be targeted at international users, but it might also bring fixes [...]
Copyright © 2007 -- This post was imported from the feed for iPhone Unlocked
(digitalfingerprint: 58ecd1847f23e654dee452ea2fbe8073 (208.65.21.16) )

Written by eas on November 9th, 2007 with no comments.
Read more articles on 1.1.2 and Apple and Update and firmware and iPhone.

iPhone Firmware 1.1.1 Released: Proceed with Caution

The new version of the iPhone Firmware has finally been released. I’d wait if you are fond of 3rd party applications or your carrier unlocked iPhone and see how things develop.  So far, it’s not looking good.  Unlocked iPhones aren’t even usable on AT&T’s network after the update, and tools for installing 3rd party apps no [...]
Copyright © 2007 -- This post was imported from the feed for iPhone Unlocked
(digitalfingerprint: 58ecd1847f23e654dee452ea2fbe8073 (208.65.21.16) )

Written by eas on September 27th, 2007 with no comments.
Read more articles on 1.1.1 and Apple and Update and firmware and iPhone.

iPhone update 1.1.1. now available

We'd like to hear from the adventurous hackers, if "bricking" has occurred. SV

iPhone v1.1.1 Update

*

Bluetooth

CVE-ID: CVE-2007-3753

Impact: An attacker within Bluetooth range may be able to cause an unexpected application termination or arbitrary code execution

Description: An input validation issue exists in the iPhone's Bluetooth server. By sending maliciously-crafted Service Discovery Protocol (SDP) packets to an iPhone with Bluetooth enabled, an attacker may trigger the issue, which may lead to unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of SDP packets. Credit to Kevin Mahaffey and John Hering of Flexilis Mobile Security for reporting this issue.

*

Mail

CVE-ID: CVE-2007-3754

Impact: Checking email over untrusted networks may lead to information disclosure via a man-in-the-middle attack

Description: When Mail is configured to use SSL for incoming and outgoing connections, it does not warn the user when the identity of the mail server has changed or cannot be trusted. An attacker capable of intercepting the connection may be able to impersonate the user's mail server and obtain the user's email credentials or other sensitive information. This update addresses the issue by properly warning when the identity of the remote mail server has changed.

*

Mail

CVE-ID: CVE-2007-3755

Impact: Following a telephone ("tel:") link in Mail will dial a phone number without confirmation

Description: Mail supports telephone ("tel:") links to dial phone numbers. By enticing a user to follow a telephone link in a mail message, an attacker can cause iPhone to place a call without user confirmation. This update addresses the issue by providing a confirmation window before dialing a phone number via a telephone link in Mail. Credit to Andi Baritchi of McAfee for reporting this issue.

*

Safari

CVE-ID: CVE-2007-3756

Impact: Visiting a malicious website may lead to the disclosure of URL contents

Description: A design issue in Safari allows a web page to read the URL that is currently being viewed in its parent window. By enticing a user to visit a maliciously crafted web page, an attacker may be able to obtain the URL of an unrelated page. This update addresses the issue through an improved cross-domain security check. Credit to Michal Zalewski of Google Inc. and Secunia Research for reporting this issue.

*

Safari

CVE-ID: CVE-2007-3757

Impact: Visiting a malicious website may lead to unintended dialing or dialing a different number than expected

Description: Safari supports telephone ("tel:") links to dial phone numbers. When a telephone link is selected, Safari will confirm that the number should be dialed. A maliciously crafted telephone link may cause a different number to be displayed during confirmation than the one actually dialed. Exiting Safari during the confirmation process may result in unintentional confirmation. This update addresses the issue by properly displaying the number that will be dialed, and requiring confirmation for telephone links. Credit to Billy Hoffman and Bryan Sullivan of HP Security Labs (formerly SPI Labs) and Eduardo Tang for reporting this issue.

*

Safari

CVE-ID: CVE-2007-3758

Impact: Visiting a malicious website may lead to cross-site scripting

Description: A cross-site scripting vulnerability exists in Safari that allows malicious websites to set JavaScript window properties of websites served from a different domain. By enticing a user to visit a maliciously crafted website, an attacker can trigger the issue, resulting in getting or setting the window status and location of pages served from other websites. This update addresses the issue by providing improved access controls on these properties. Credit to Michal Zalewski of Google Inc. for reporting this issue.

*

Safari

CVE-ID: CVE-2007-3759

Impact: Disabling JavaScript does not take effect until Safari is restarted

Description: Safari can be configured to enable or disable JavaScript. This preference does not take effect until the next time Safari is restarted. This usually occurs when the iPhone is restarted. This may mislead users into believing that JavaScript is disabled when it is not. This update addresses the issue by applying the new preference prior to loading new web pages.

*

Safari

CVE-ID: CVE-2007-3760

Impact: Visiting a malicious website may result in cross-site scripting

Description: A cross-site scripting issue in Safari allows a maliciously crafted website to bypass the same-origin policy using "frame" tags. By enticing a user to visit a maliciously crafted web page, an attacker can trigger the issue, which may lead to the execution of JavaScript in the context of another site. This update addresses the issue by disallowing JavaScript as an "iframe" source, and limiting JavaScript in frame tags to the same access as the site from which it was served. Credit to Michal Zalewski of Google Inc. and Secunia Research for reporting this issue.

*

Safari

CVE-ID: CVE-2007-3761

Impact: Visiting a malicious website may result in cross-site scripting

Description: A cross-site scripting issue in Safari allows JavaScript events to be associated with the wrong frame. By enticing a user to visit a maliciously crafted web page, an attacker may cause the execution of JavaScript in the context of another site. This update addresses the issue by associating JavaScript events to the correct source frame.

*

Safari

CVE-ID: CVE-2007-4671

Impact: JavaScript on websites may access or manipulate the contents of documents served over HTTPS

Description: An issue in Safari allows content served over HTTP to alter or access content served over HTTPS in the same domain. By enticing a user to visit a maliciously crafted web page, an attacker may cause the execution of JavaScript in the context of HTTPS web pages in that domain. This update addresses the issue by limiting access between JavaScript executing in HTTP and HTTPS frames. Credit to Keigo Yamazaki of LAC Co., Ltd. (Little eArth Corporation Co., Ltd.) for reporting this issue.

Installation note:

This update is only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an internet connection and have installed the latest version of iTunes from www.apple.com/itunes

iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting "Don't install" will present the option the next time you connect your iPhone.

Apple

Written by Salvatore Volpe MD FAAP FACP CHCQM on September 27th, 2007 with no comments.
Read more articles on Update.

Apple Casts Fear, Uncertainty, and Doubt Over Unlocked iPhones

I warned you to be cautious about buying an iPhone with the intent of unlocking it for use with another carrier. Today, Apple issued their own warning as the intro to a press release about the next iPhone update, due later this week. Apple claims that “many of the unauthorized iPhone unlocking programs available on [...]
Copyright © 2007 -- This post was imported from the feed for iPhone Unlocked
(digitalfingerprint: 58ecd1847f23e654dee452ea2fbe8073 (208.65.21.16) )

Written by eas on September 24th, 2007 with no comments.
Read more articles on Apple and FUD and Update and relock and unlock and unlocked.

« Older articles

No newer articles