Apple iPhone, iPod Touch security patch: What's fixed

Version 3.1.3 of software patches several security holes and provides a few bug fixes and minor enhancements.

Apple on Tuesday released an updated version of its iPhone OS software for the iPhone and iPod touch. The new version 3.1.3 patches several security holes, provides a few bug fixes and minor enhancements, and is available via iTunes download.

The five security fixes are related to CoreAudio, ImageIO, Recovery Mode and WebKit.

The CoreAudio patch prevents "maliciously crafted" MP4 audio files from wreaking havoc, such as terminating programs or running rogue code. The ImageIO fix blocks malicious TIFF images from performing similar voodoo when users view them.

The Recovery Mode update prevents someone with physical access to a locked iPhone or iPod touch from bypassing the passcode and accessing your data. It corrects a memory corruption glitch in the handling of a USB control message that allowed the security breach.

WebKit gets two patches. One corrects an HTML 5-related problem that may cause mail to load remote audio and video files when remote image-loading is turned off. The second blocks WebKit from accessing a malicious FTP server.

The minor upgrades in iPhone OS version 3.1.3 correct a bug that causes apps to crash when using a Japanese Kana keyboard, and improve the accuracy of battery-level reporting on the iPhone 3GS.

The iPhone OS patch comes hot on the heels of Monday's iTunes 9.0.3 update, which remedies the problem of iTunes forgetting user passwords, and fixes glitches with iPod syncing. It also improves iTunes' stability and performance.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags iPhonemp3 playersipod touch

More about Apple

Show Comments
[]