CVE-2014-4480: Critical severity iphone os vulnerability
Published Jan 30, 2015
·Updated
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.
Affected Software
2 affected components
iPhone OS<=8.1.2
tvOS<=7.0.1
Event History
Jan 30, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4480?
CVE-2014-4480 is rated as high severity due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2014-4480?
To mitigate CVE-2014-4480, update your Apple iOS to version 8.1.3 or later, or Apple TV to version 7.0.3 or later.
3
Which devices are affected by CVE-2014-4480?
CVE-2014-4480 affects Apple iOS versions before 8.1.3 and Apple TV versions before 7.0.3.
4
What type of vulnerability is CVE-2014-4480?
CVE-2014-4480 is a directory traversal vulnerability that allows attackers to access unintended filesystem locations.
5
Can CVE-2014-4480 be exploited remotely?
Yes, CVE-2014-4480 could potentially be exploited remotely if an attacker can manipulate symlinks.