First published: Tue Jul 01 2014(Updated: )
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=7.1.1 | |
iPhone OS | =7.0 | |
iPhone OS | =7.0.1 | |
iPhone OS | =7.0.2 | |
iPhone OS | =7.0.3 | |
iPhone OS | =7.0.4 | |
iPhone OS | =7.0.5 | |
iPhone OS | =7.0.6 | |
iPhone OS | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1348 is considered a high severity vulnerability due to the exposure of sensitive information.
To mitigate CVE-2014-1348, users should upgrade to iOS version 7.1.2 or later, which addresses this flaw.
CVE-2014-1348 affects the cleartext attachments stored by the Mail application, allowing sensitive information to be exposed.
Users of Apple iOS versions before 7.1.2 are at risk from CVE-2014-1348, especially if they handle sensitive attachments.
CVE-2014-1348 affects all devices running Apple iOS versions 7.0 to 7.1.1.