CVE-2014-1252: Double Free
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1252?
CVE-2014-1252 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2014-1252?
To fix CVE-2014-1252, upgrade to Apple Pages version 2.1 or later for 2.x, and version 5.1 or later for 5.x.
What systems are affected by CVE-2014-1252?
CVE-2014-1252 affects Apple Pages versions 2.0 through 2.0.2 and 5.0 through 5.0.1, as well as specific versions of macOS and iPhone OS up to 10.9.1 and 7.0 respectively.
What type of attack can be executed using CVE-2014-1252?
An attacker can use a crafted Microsoft Word file to exploit CVE-2014-1252, potentially leading to arbitrary code execution or crashing the application.
Is there a workaround for CVE-2014-1252?
Currently, there are no publicly documented workarounds for CVE-2014-1252 other than upgrading to a safe version of Apple Pages.