Apple iOS CVE-2014-4448 Encryption Security Weakness
BID:70661
Info
Apple iOS CVE-2014-4448 Encryption Security Weakness
| Bugtraq ID: | 70661 |
| Class: | Design Error |
| CVE: |
CVE-2014-4448 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2014 12:00AM |
| Updated: | Oct 20 2014 12:00AM |
| Credit: | Jonathan Zdziarski, and Kevin DeLong. |
| Vulnerable: |
Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 |
| Not Vulnerable: | |
Discussion
Apple iOS CVE-2014-4448 Encryption Security Weakness
Apple iOS is prone to a security weakness that may allow attackers to obtain sensitive information.
Successfully exploiting this issue may allow attackers to view encrypted data and obtain sensitive information. This may lead to other attacks.
Apple iOS is prone to a security weakness that may allow attackers to obtain sensitive information.
Successfully exploiting this issue may allow attackers to view encrypted data and obtain sensitive information. This may lead to other attacks.
Exploit / POC
Apple iOS CVE-2014-4448 Encryption Security Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Apple iOS CVE-2014-4448 Encryption Security Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.