PT-2014-5849 · Apple · Libnotify

Published

2014-09-18

·

Updated

2019-03-08

·

CVE-2014-4381

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Libnotify versions prior to 8 (in Apple iOS) Libnotify versions prior to 7 (in Apple TV)
Description The issue is related to a lack of proper bounds checking on write operations in Libnotify, which can be exploited by attackers to execute arbitrary code as root via a crafted application.
Recommendations For Libnotify in Apple iOS versions prior to 8, update to version 8 or later. For Libnotify in Apple TV versions prior to 7, update to version 7 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4381

Affected Products

Libnotify