CVE-2014-1257: Low severity Apple iOS and macOS vulnerability
Published Feb 27, 2014
·Updated
CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
Affected Software
7 affected components
Apple iOS and macOS<=10.8.5
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Apple iOS and macOS=10.8.4
Apple iOS and macOS=10.8.5
Event History
Feb 27, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1257?
CVE-2014-1257 has a medium severity rating as it allows unauthorized access to session cookies.
2
How do I fix CVE-2014-1257?
To fix CVE-2014-1257, you should update your macOS to a version later than 10.8.5.
3
Who is affected by CVE-2014-1257?
CVE-2014-1257 affects users of Apple OS X versions from 10.8.0 to 10.8.5.
4
What type of attacks can CVE-2014-1257 lead to?
CVE-2014-1257 can lead to session hijacking if an unattended workstation is exploited.
5
What software is impacted by CVE-2014-1257?
CVE-2014-1257 specifically impacts the CFNetwork component in Apple OS X.