First published: Thu Sep 18 2014(Updated: )
Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=7.1.2 | |
iPhone OS | =7.0 | |
iPhone OS | =7.0.1 | |
iPhone OS | =7.0.2 | |
iPhone OS | =7.0.3 | |
iPhone OS | =7.0.4 | |
iPhone OS | =7.0.5 | |
iPhone OS | =7.0.6 | |
iPhone OS | =7.1 | |
iPhone OS | =7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4366 has a medium severity rating due to the exposure of sensitive information.
CVE-2014-4366 allows remote attackers to intercept sensitive cleartext information from users' Mail on iOS devices.
CVE-2014-4366 affects Apple iOS versions prior to 8, including all 7.x versions up to 7.1.1.
To mitigate CVE-2014-4366, users should update their devices to at least iOS 8 or later.
A temporary workaround for CVE-2014-4366 is to avoid using IMAP with servers that have LOGIN disabled.