CVE-2014-4455: Low severity iphone os vulnerability
Published Nov 18, 2014
·Updated
dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.
Affected Software
12 affected components
iPhone OS<=8.1.2
tvOS<=7.0.1
tvOS=6.0
tvOS=6.0.1
tvOS=6.0.2
tvOS=6.1
tvOS=6.1.1
tvOS=6.1.2
tvOS=6.2
tvOS=6.2.1
tvOS=7.0
tvOS=7.0.1
Event History
Nov 18, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4455?
CVE-2014-4455 is rated as a high severity vulnerability due to its potential to bypass code-signing restrictions.
2
How do I fix CVE-2014-4455?
To fix CVE-2014-4455, update affected devices to Apple iOS version 8.1.2 or later, or Apple TV version 7.0.2 or later.
3
Which versions of iOS are affected by CVE-2014-4455?
CVE-2014-4455 affects Apple iOS versions before 8.1.1.
4
Which versions of tvOS are affected by CVE-2014-4455?
CVE-2014-4455 impacts all tvOS versions before 7.0.2 and specific earlier versions.
5
What type of attack does CVE-2014-4455 enable?
CVE-2014-4455 enables local users to execute arbitrary code by bypassing code-signing restrictions.