CVE-2014-1274: Infoleak
Published Mar 14, 2014
·Updated
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.
Affected Software
7 affected components
apple iPhone OS<=7.0.6
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
Event History
Mar 14, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1274?
CVE-2014-1274 has a medium severity rating due to the potential for attackers to access sensitive contact information.
2
How do I fix CVE-2014-1274?
To fix CVE-2014-1274, update your Apple iOS to version 7.1 or later.
3
Who is affected by CVE-2014-1274?
CVE-2014-1274 affects users of Apple iOS versions prior to 7.1.
4
What type of attack is CVE-2014-1274?
CVE-2014-1274 is a physical proximity attack that can be executed via the lock screen.
5
What information is exposed by CVE-2014-1274?
CVE-2014-1274 allows attackers to obtain sensitive FaceTime contact information.