CVE-2014-4383: Input Validation
Published Sep 18, 2014
·Updated
The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's update status via a crafted Last-Modified HTTP response header.
Affected Software
17 affected components
iPhone OS<=7.1.2
iPhone OS=7.0
iPhone OS=7.0.1
iPhone OS=7.0.2
iPhone OS=7.0.3
iPhone OS=7.0.4
iPhone OS=7.0.5
iPhone OS=7.0.6
iPhone OS=7.1
iPhone OS=7.1.1
tvOS<=6.2
tvOS=6.0
tvOS=6.0.1
tvOS=6.0.2
tvOS=6.1
tvOS=6.1.1
tvOS=6.1.2
Event History
Sep 18, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4383?
CVE-2014-4383 has a medium severity level, allowing man-in-the-middle attacks.
2
How do I fix CVE-2014-4383?
To fix CVE-2014-4383, upgrade to iOS version 8 or later or update tvOS to the latest version.
3
What devices are affected by CVE-2014-4383?
CVE-2014-4383 affects devices running iOS versions prior to 8 and tvOS versions earlier than 7.
4
What is the type of attack associated with CVE-2014-4383?
CVE-2014-4383 is associated with man-in-the-middle attacks that can spoof update statuses.
5
Does CVE-2014-4383 allow data interception?
While CVE-2014-4383 does not directly enable data interception, it does facilitate spoofing of critical device updates.