CVE-2014-4480
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: product-security@apple.com — http://support.apple.com/HT204246
Vendor advisory: product-security@apple.com — http://support.apple.com/HT204245
Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
Vendor advisory: product-security@apple.com — http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| macos | affected | |
References
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
- http://support.apple.com/HT204245
- http://support.apple.com/HT204246
- http://www.securityfocus.com/bid/72334
- http://www.securitytracker.com/id/1031652
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
- http://support.apple.com/HT204245
- http://support.apple.com/HT204246
- http://www.securityfocus.com/bid/72334
- http://www.securitytracker.com/id/1031652
CWEs
CWE-59
Verify integrity in audit chain (admin only). AS-IS.