CVE-2014-4477: Buffer Overflow
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4476 and CVE-2014-4479.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4477?
CVE-2014-4477 is classified as a critical vulnerability because it allows remote attackers to execute arbitrary code.
How do I fix CVE-2014-4477?
To mitigate CVE-2014-4477, update Apple devices to iOS version 8.1.3 or later, Safari version 6.2.3 or later, and Apple TV version 7.0.3 or later.
What systems are affected by CVE-2014-4477?
CVE-2014-4477 affects Apple iOS, Apple Safari, Apple iTunes, and tvOS prior to their respective patched versions.
What types of attacks can CVE-2014-4477 facilitate?
CVE-2014-4477 can facilitate remote code execution and denial of service attacks through crafted web content.
Is there a workaround for CVE-2014-4477?
There are no known workarounds for CVE-2014-4477; the best approach is to apply updates as soon as they are available.