First published: Fri Mar 14 2014(Updated: )
The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requirements via a long name.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=6.0.2 | |
tvOS | =6.0 | |
tvOS | =6.0.1 | |
iPhone OS | <=7.0.6 | |
iPhone OS | =7.0 | |
iPhone OS | =7.0.1 | |
iPhone OS | =7.0.2 | |
iPhone OS | =7.0.3 | |
iPhone OS | =7.0.4 | |
iPhone OS | =7.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1282 has a medium severity rating due to its potential for bypassing configuration-profile visibility requirements.
To fix CVE-2014-1282, update Apple iOS to version 7.1 or higher and Apple TV to version 6.1 or higher.
CVE-2014-1282 exploits weaknesses in the Profiles component of older Apple iOS and Apple TV versions.
Users running Apple iOS versions prior to 7.1 and Apple TV versions prior to 6.1 are affected by CVE-2014-1282.
The impact of CVE-2014-1282 includes unauthorized access to sensitive configuration profiles.