Secunia has put out an advisory about a vulnerability in the iPhone and iPod touch. Viewing a malformed TIFF image can cause attacker-supplied code to be run. the only workaround of which we're aware is not viewing TIFF images from unknown sources. We understand there is active exploit code in the wild for this vulnerability.
There are more details at
http://secunia.com/advisories/27213/ . The Metasploit project has more specifics on the exploit and a link to exploit code at
http://blog.metasploit.com/2007/10/c...e-part-21.html . The CVE entry can be found at
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5450 .
More...