CVE Vulnerabilities

CVE-2014-1252

Double Free

Published: Jan 24, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Pages Apple 2.0 (including) 2.0 (including)
Pages Apple 2.0.1 (including) 2.0.1 (including)
Pages Apple 2.0.2 (including) 2.0.2 (including)
Pages Apple 5.0 (including) 5.0 (including)
Pages Apple 5.0.1 (including) 5.0.1 (including)

Potential Mitigations

References