Apple iOS and TV CVE-2014-4357 Local Information Disclosure Security Vulnerability
BID:69930
Info
Apple iOS and TV CVE-2014-4357 Local Information Disclosure Security Vulnerability
| Bugtraq ID: | 69930 |
| Class: | Design Error |
| CVE: |
CVE-2014-4357 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 17 2014 12:00AM |
| Updated: | Sep 17 2014 12:00AM |
| Credit: | Heli Myllykoski of OP-Pohjola Group |
| Vulnerable: |
Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 7.0.6 Apple iOS 7.0.3 Apple iOS 7.0.2 Apple iOS 7.0.1 Apple iOS 6.3.1 Apple iOS 6.1.6 Apple iOS 6.1.4 Apple iOS 6.1.3 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 7.1.2 Apple iOS 7.1.1 Apple iOS 7.1 Apple iOS 7.0.4 Apple iOS 7 Apple iOS 6.1 Apple iOS 6.0.2 Apple iOS 6.0.1 Apple iOS 6 for Developer Apple iOS 6 Beta 4 Apple iOS 6 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 Apple Apple TV 6.0.2 Apple Apple TV 5.2.1 Apple Apple TV 5.1.1 Apple Apple TV 4.4.2 Apple Apple TV 4.4 Apple Apple TV 6.1.2 Apple Apple TV 6.1.1 Apple Apple TV 6.1 Apple Apple TV 6.0.1 Apple Apple TV 6.0 Apple Apple TV 5.2 Apple Apple TV 5.1.0 Apple Apple TV 5.1 Apple Apple TV 5.0.2 Apple Apple TV 5.0.1 Apple Apple TV 5.0.0 Apple Apple TV 5.0 Apple Apple TV 4.4.4 Apple Apple TV 4.4.3 Apple Apple TV 4.4 Apple Apple TV 4.3.0 Apple Apple TV 4.3 Apple Apple TV 4.2.2 Apple Apple TV 4.2.1 Apple Apple TV 4.2.0 Apple Apple TV 4.2 Apple Apple TV 4.1.1 Apple Apple TV 4.1.0 Apple Apple TV 4.1 Apple Apple TV 4.0 Apple Apple TV 3.0.2 Apple Apple TV 3.0.1 Apple Apple TV 3.0.0 Apple Apple TV 2.4.0 Apple Apple TV 2.3.1 Apple Apple TV 2.3.0 Apple Apple TV 2.2.0 Apple Apple TV 2.1 Apple Apple TV 1.0 |
| Not Vulnerable: |
Apple iOS 8 Apple Apple TV 7 |
Exploit / POC
Apple iOS and TV CVE-2014-4357 Local Information Disclosure Security Vulnerability
An attacker with physical access to the device can exploit this issue.
An attacker with physical access to the device can exploit this issue.
Solution / Fix
Apple iOS and TV CVE-2014-4357 Local Information Disclosure Security Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apple iOS and TV CVE-2014-4357 Local Information Disclosure Security Vulnerability
References:
References:
- iOS Homepage (Apple)
- iPad Homepage (Apple)
- iPhone Homepage (Apple)
- iPod touch Product Page (Apple)
- About the security content of Apple TV 7 (Apple)
- About the security content of iOS 8 (Apple)