CVE-2014-1278Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS

Severity
7.2HIGHNVD
EPSS
0.0%
top 88.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 14

Description

The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafted call.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

NVDapple/tvos6.0.2+2
NVDapple/iphone_os7.0.6+6

🔴Vulnerability Details

1
GHSA
GHSA-fwf3-wwfv-qhwm: The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 72022-05-14