CVE-2014-1349: Use After Free
Published Jul 1, 2014
·Updated
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
Affected Software
9 affected components
apple iPhone OS<=7.1.1
apple iPhone OS=7.0
apple iPhone OS=7.0.1
apple iPhone OS=7.0.2
apple iPhone OS=7.0.3
apple iPhone OS=7.0.4
apple iPhone OS=7.0.5
apple iPhone OS=7.0.6
apple iPhone OS=7.1
Event History
Jul 1, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1349?
CVE-2014-1349 has high severity due to the potential for remote code execution and application crashes.
2
How do I fix CVE-2014-1349?
To fix CVE-2014-1349, update your Apple iOS device to version 7.1.2 or later.
3
What versions of Apple iOS are affected by CVE-2014-1349?
CVE-2014-1349 affects all Apple iOS versions prior to 7.1.2, including 7.0 through 7.1.1.
4
What type of vulnerability is CVE-2014-1349?
CVE-2014-1349 is a use-after-free vulnerability found in Safari on Apple iOS.
5
Can CVE-2014-1349 lead to denial of service?
Yes, CVE-2014-1349 can cause a denial of service by crashing the application due to the vulnerability.