CVE-2014-4471: Medium severity itunes vulnerability
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4471?
CVE-2014-4471 is rated as a high severity vulnerability that allows remote code execution and denial of service.
How do I fix CVE-2014-4471?
To fix CVE-2014-4471, update to the latest version of Safari, iTunes, or tvOS that addresses this vulnerability.
Which versions of Safari are affected by CVE-2014-4471?
CVE-2014-4471 affects Safari versions before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1.
Can CVE-2014-4471 affect iOS devices?
Yes, CVE-2014-4471 can affect Apple iPhone OS versions up to and including 8.1.2.
What kind of attack can exploit CVE-2014-4471?
CVE-2014-4471 can be exploited through crafted web pages to execute arbitrary code or cause application crashes.