First published: Fri Jan 30 2015(Updated: )
UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, which allows local users to obtain sensitive information by reading a file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.10.0 | |
macOS Yosemite | =10.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8834 is considered a moderate severity vulnerability.
CVE-2014-8834 allows local users to access sensitive information by reading a printing preference file that stores a PDF document's password.
CVE-2014-8834 affects Apple OS X versions 10.10.0 and 10.10.1.
To mitigate CVE-2014-8834, users should upgrade to OS X 10.10.2 or later.
Yes, a patch for CVE-2014-8834 was included in the OS X 10.10.2 update.