First published: Wed Apr 23 2014(Updated: )
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=7.1 | |
iPhone OS | =7.0 | |
iPhone OS | =7.0.1 | |
iPhone OS | =7.0.2 | |
iPhone OS | =7.0.3 | |
iPhone OS | =7.0.4 | |
iPhone OS | =7.0.5 | |
iPhone OS | =7.0.6 | |
Apple iOS and macOS | =10.9 | |
Apple iOS and macOS | =10.9.1 | |
Apple iOS and macOS | =10.9.2 | |
tvOS | <=6.1 | |
tvOS | =6.0 | |
tvOS | =6.0.1 | |
tvOS | =6.0.2 | |
Apple iOS and macOS | =10.8.0 | |
Apple iOS and macOS | =10.8.1 | |
Apple iOS and macOS | =10.8.2 | |
Apple iOS and macOS | =10.8.3 | |
Apple iOS and macOS | =10.8.4 | |
Apple iOS and macOS | =10.8.5 | |
Apple iOS and macOS | =10.8.5-supplemental_update | |
<=7.1 | ||
=7.0 | ||
=7.0.1 | ||
=7.0.2 | ||
=7.0.3 | ||
=7.0.4 | ||
=7.0.5 | ||
=7.0.6 | ||
=10.9 | ||
=10.9.1 | ||
=10.9.2 | ||
<=6.1 | ||
=6.0 | ||
=6.0.1 | ||
=6.0.2 | ||
=10.8.0 | ||
=10.8.1 | ||
=10.8.2 | ||
=10.8.3 | ||
=10.8.4 | ||
=10.8.5 | ||
=10.8.5-supplemental_update |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1295 has been classified as a high severity vulnerability due to its potential to allow man-in-the-middle attacks.
To address CVE-2014-1295, update your Apple iOS, macOS, or tvOS to the latest version that is not affected by the vulnerability.
CVE-2014-1295 affects Apple iOS versions before 7.1.1, macOS 10.8.x and 10.9.x before 10.9.2, and tvOS before 6.1.1.
CVE-2014-1295 enables man-in-the-middle attacks, allowing attackers to intercept and access sensitive information during network sessions.
Yes, CVE-2014-1295 is an implementation flaw in Apple's Secure Transport that fails to verify server X.509 certificates during renegotiation.