Apple Mac OS X and iOS XML external entity information leakage (CVE-2014-4374)
Release date:
Updated on:
Affected Systems:
Apple Mac OS X <8
Description:
Bugtraq id: 69905
CVE (CAN) ID: CVE-2014-4374
OS x (formerly Mac OS X) is the latest version of Apple's exclusive operating system developed for Mac tower computers.
NSXMLParser in earlier versions of the Foundation of Apple iOS 8 has a security vulnerability that allows attackers to read arbitrary files by using XML data and entity references that contain external entity declarations.
<* Source: George Gal
Link: https://www.apple.com/support/security/pgp/
*>
Suggestion:
Vendor patch:
Apple
-----
Apple has released a Security Bulletin (APPLE-SA-2014-09-17-5) and patches for this:
APPLE-SA-2014-09-17-5: OS X Server 3.2.1
Link: https://www.apple.com/support/security/pgp/
This article permanently updates the link address: