CVE-2014-1361: Infoleak
Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1361?
CVE-2014-1361 is classified as a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2014-1361?
To mitigate CVE-2014-1361, update your Apple iOS, macOS, or tvOS to the latest version, as the issue has been addressed in subsequent releases.
What systems are affected by CVE-2014-1361?
CVE-2014-1361 affects Apple iOS versions prior to 7.1.2, OS X versions prior to 10.9.4, and Apple TV versions prior to 6.1.2.
What type of vulnerability is CVE-2014-1361?
CVE-2014-1361 is a memory corruption vulnerability that occurs due to improper management of DTLS connections.
Can I still use my device with CVE-2014-1361?
Although you can still use your device, it is highly recommended to apply the available security updates to protect against CVE-2014-1361.