CERT-In Advisory
CIAD-2014-0056
Multiple Vulnerabilities in Apple iOS
Original Issue Date: September 25, 2014
Severity Rating: High
Systems Affected
- Apple iOS versions prior to 8
Overview
Multiple vulnerabilities have been reported in Apple iOS which could allow an attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions or cause Denial of Service (DoS) conditions.
Description
These vulnerabilities occur due to an error in LEAP authentication, a logic issue while handling events in AssistiveTouch, race condition and path traversal issue in App installation, improper bounds checking in CoreGraphics and IOHIDFamily, improper handling of XML in NSXMLParser, null pointer dereference issue in IOAcceleratorFamily, insufficient validation in IOKit, improper restrictions in auto filling of passwords in forms in Safari and various memory corruption and race condition issues.
Successful exploitation of these vulnerabilities could allow a remote attacker to gain access to sensitive information, bypass security restrictions or cause Denial of Service (DoS) conditions.
A local attacker could also exploit these vulnerabilities to bypass security restrictions and gain access to a targeted device. The attacker could use this access to run un-trusted third-party applications to gain access to sensitive information or to execute arbitrary code with elevated privileges on an affected device.
Solution
Upgrade to Apple iOS 8
http://support.apple.com/kb/HT6441
Vendor Information
Apple
http://support.apple.com/kb/HT6441
References
Apple
http://support.apple.com/kb/HT6441
SecurityTracker
http://www.securitytracker.com/id/1030866
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=35756
SecurityFocus
http://www.securityfocus.com/bid/69882/
CVE Name
CVE-2014-4352
CVE-2014-4353
CVE-2014-4354
CVE-2014-4356
CVE-2014-4357
CVE-2014-4361
CVE-2014-4362
CVE-2014-4363
CVE-2014-4364
CVE-2014-4366
CVE-2014-4367
CVE-2014-4368
CVE-2014-4369
CVE-2014-4371
CVE-2014-4372
CVE-2014-4373
CVE-2014-4374
CVE-2014-4375
CVE-2014-4377
CVE-2014-4378
CVE-2014-4379
CVE-2014-4380
CVE-2014-4381
CVE-2014-4383
CVE-2014-4384
CVE-2014-4386
CVE-2014-4388
CVE-2014-4389
CVE-2014-4404
CVE-2014-4405
CVE-2014-4407
CVE-2014-4408
CVE-2014-4409
CVE-2014-4410
CVE-2014-4411
CVE-2014-4412
CVE-2014-4413
CVE-2014-4414
CVE-2014-4415
CVE-2014-4418
CVE-2014-4419
CVE-2014-4420
CVE-2014-4421
CVE-2014-4422
CVE-2014-4423
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|