CVE-2014-4371: Low severity Apple tvOS vulnerability
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4371?
CVE-2014-4371 has been classified as a high-severity vulnerability.
How do I fix CVE-2014-4371?
To fix CVE-2014-4371, update your device to the latest version of Apple iOS or tvOS that contains the necessary security patches.
Which versions are affected by CVE-2014-4371?
CVE-2014-4371 affects Apple iOS versions before 8 and Apple TV versions before 7.
What impact does CVE-2014-4371 have on my device?
CVE-2014-4371 allows attackers to obtain sensitive memory content and layout information via a crafted application.
Is there a workaround for CVE-2014-4371?
There are no official workarounds for CVE-2014-4371, and the best defense is to apply the latest updates provided by Apple.