CVE Vulnerabilities

CVE-2014-4496

Published: Jan 30, 2015 | Modified: Mar 08, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The mach_port_kobject interface in the kernel in Apple iOS before 8.1.3 and Apple TV before 7.0.3 does not properly restrict kernel-address and heap-permutation information, which makes it easier for attackers to bypass the ASLR protection mechanism via a crafted app.

Affected Software

Name Vendor Start Version End Version
Iphone_os Apple * 8.1.2 (including)
Tvos Apple * 7.0.1 (including)

References