CVE-2014-1356: Buffer Overflow
Published Jul 1, 2014
·Updated
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages.
Affected Software
18 affected components
Apple iOS and macOS=10.9
Apple iOS and macOS=10.9.1
Apple iOS and macOS=10.9.2
Apple iOS and macOS=10.9.3
Apple iPhone OS<=7.1.1
Apple iPhone OS=7.0
Apple iPhone OS=7.0.1
Apple iPhone OS=7.0.2
Apple iPhone OS=7.0.3
Apple iPhone OS=7.0.4
Apple iPhone OS=7.0.5
Apple iPhone OS=7.0.6
Apple iPhone OS=7.1
Apple tvOS<=6.1.1
Apple tvOS=6.0
Apple tvOS=6.0.1
Apple tvOS=6.0.2
Apple tvOS=6.1
Event History
Jul 1, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1356?
CVE-2014-1356 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2014-1356?
To fix CVE-2014-1356, users should update their Apple devices to iOS 7.1.2, OS X 10.9.4, or tvOS 6.1.2.
3
What systems are affected by CVE-2014-1356?
CVE-2014-1356 affects Apple iOS versions prior to 7.1.2, OS X versions prior to 10.9.4, and tvOS versions prior to 6.1.2.
4
What type of attack does CVE-2014-1356 enable?
CVE-2014-1356 enables attackers to execute arbitrary code via specially crafted IPC messages.
5
When was CVE-2014-1356 discovered?
CVE-2014-1356 was reported publicly in June 2014.