CVE-2014-1272Link Following in Apple Iphone OS

CWE-59Link Following2 documents2 sources
Severity
6.3MEDIUMNVD
EPSS
0.0%
top 92.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 14

Description

CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.

CVSS vector

AV:L/AC:M/C:N/I:C/A:CExploitability: 3.4 | Impact: 9.2

Affected Packages2 packages

NVDapple/tvos6.0.2+2
NVDapple/iphone_os7.0.6+6

🔴Vulnerability Details

1
GHSA
GHSA-xq6p-x243-2jpw: CrashHouseKeeping in Crash Reporting in Apple iOS before 72022-05-14