CVE-2014-4473: Medium severity itunes vulnerability
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4473?
CVE-2014-4473 has a medium severity rating as it allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2014-4473?
To fix CVE-2014-4473, upgrade to Apple Safari version 6.2.1 or later, or update your affected devices with the latest security patches.
Which software is affected by CVE-2014-4473?
CVE-2014-4473 affects Apple Safari versions prior to 6.2.1, as well as specific versions of iTunes, iPhone OS, and tvOS.
What are the risks of CVE-2014-4473?
The risks associated with CVE-2014-4473 include the potential for remote code execution and application crashes leading to denial of service.
What should users of affected software do regarding CVE-2014-4473?
Users of affected software should immediately update their applications and devices to the latest versions to mitigate the risks posed by CVE-2014-4473.