Apple iPhone contains a flaw that is triggered during the handling of a crafted User Data Header (UDH), which may allow an attacker to spoof SMS messages. This will cause the reply address to be spoofed so that the incorrect address is displayed on the recipients message.
Classification
Location:
Remote / Network Access,
Mobile Phone / Hand-held Device
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Private
Disclosure:
Uncoordinated Disclosure
Solution
OSVDB is not aware of a solution for this vulnerability.