CVE-2014-4357: Infoleak
Published Sep 18, 2014
·Updated
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
Affected Software
17 affected components
tvOS<=6.2
tvOS=6.0
tvOS=6.0.1
tvOS=6.0.2
tvOS=6.1
tvOS=6.1.1
tvOS=6.1.2
iPhone OS<=7.1.2
iPhone OS=7.0
iPhone OS=7.0.1
iPhone OS=7.0.2
iPhone OS=7.0.3
iPhone OS=7.0.4
iPhone OS=7.0.5
iPhone OS=7.0.6
iPhone OS=7.1
iPhone OS=7.1.1
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4357?
CVE-2014-4357 is classified as a medium severity vulnerability affecting certain versions of Apple iOS and tvOS.
2
How do I fix CVE-2014-4357?
To mitigate CVE-2014-4357, update your Apple device to the latest version of iOS or tvOS available.
3
Who is affected by CVE-2014-4357?
CVE-2014-4357 affects users of Apple iOS versions before 8 and Apple TV versions before 7.
4
What type of information can be exposed due to CVE-2014-4357?
CVE-2014-4357 allows attackers to obtain sensitive information that may be present in log data.
5
Is there a patch available for CVE-2014-4357?
Yes, Apple has released updates that address the vulnerabilities associated with CVE-2014-4357.