First published: Tue Jul 01 2014(Updated: )
Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=6.1.1 | |
tvOS | =6.0 | |
tvOS | =6.0.1 | |
tvOS | =6.0.2 | |
tvOS | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-1383 is considered moderate due to the risk of unauthorized purchase transactions.
To fix CVE-2014-1383, update your Apple TV to version 6.1.2 or later.
Users running Apple TV versions 6.1.1 and earlier are affected by CVE-2014-1383.
CVE-2014-1383 involves bypassing a password requirement for iTunes Store purchases.
Yes, CVE-2014-1383 allows remote authenticated users to exploit the vulnerability.