Multiple Apple product PDF handle Integer Overflow Vulnerability (CVE-2014-4377)
Release date:
Updated on:
Affected Systems:
Apple iOS <8
Description:
Bugtraq id: 69903
CVE (CAN) ID: CVE-2014-4377
IOS is an operating system developed by Apple for mobile devices. It supports iPhone, iPod touch, iPad, and Apple TV. Apple TV is a digital multi-media machine designed, marketed, and sold by Apple.
In versions earlier than Apple iOS 8 and earlier than Apple TV 7, CoreGraphics has the integer overflow vulnerability. Remote attackers construct PDF files, this vulnerability can cause arbitrary code execution or DoS (application crash ).
<* Source: Felipe Andres Manzano
Link: http://blog.binamuse.com/2014/09/coregraphics-memory-corruption.html
*>
Test method:
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Felipe Andres Manzano () provides the following test methods:
Https://github.com/feliam/CVE-2014-4377
Suggestion:
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apple.com/support/downloads/
Http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html
Http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html
This article permanently updates the link address: