CVE-2014-1256: Buffer Overflow
Published Feb 27, 2014
·Updated
Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.
Affected Software
21 affected components
Apple iOS and macOS<=10.9.1
Apple iOS and macOS=10.7.0
Apple iOS and macOS=10.7.1
Apple iOS and macOS=10.7.2
Apple iOS and macOS=10.7.3
Apple iOS and macOS=10.7.4
Apple iOS and macOS=10.7.5
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Apple iOS and macOS=10.8.4
Apple iOS and macOS=10.8.5
Apple iOS and macOS=10.8.5-supplemental_update
Apple iOS and macOS=10.9
Apple Mac OS X Server=10.7.0
Apple Mac OS X Server=10.7.1
Apple Mac OS X Server=10.7.2
Apple Mac OS X Server=10.7.3
Apple Mac OS X Server=10.7.4
Apple Mac OS X Server=10.7.5
Event History
Feb 27, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1256?
CVE-2014-1256 has been rated as high severity due to its potential to bypass App Sandbox protections.
2
How do I fix CVE-2014-1256?
To fix CVE-2014-1256, upgrade to OS X version 10.9.2 or later, as this version includes the necessary patches.
3
What are the affected versions for CVE-2014-1256?
CVE-2014-1256 affects Apple OS X versions prior to 10.9.2, including 10.7.x and 10.8.x.
4
Can CVE-2014-1256 be exploited remotely?
Yes, CVE-2014-1256 can be exploited remotely through crafted Mach messages.
5
What are the potential impacts of CVE-2014-1256?
The potential impacts of CVE-2014-1256 include unauthorized access and execution of malicious code, compromising system integrity.