First published: Tue Jul 01 2014(Updated: )
iBooks Commerce in Apple OS X before 10.9.4 places Apple ID credentials in the iBooks log, which allows local users to obtain sensitive information by reading this file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.9 | |
macOS Yosemite | =10.9.1 | |
macOS Yosemite | =10.9.2 | |
macOS Yosemite | =10.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1317 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To remediate CVE-2014-1317, update your macOS to version 10.9.4 or later.
CVE-2014-1317 exposes Apple ID credentials stored in the iBooks log file, which could be accessed by local users.
CVE-2014-1317 affects macOS versions 10.9, 10.9.1, 10.9.2, and 10.9.3.
CVE-2014-1317 is a local vulnerability, as it requires access to the affected machine to exploit.