CVE-2014-8611
published 2015-09-18CVE-2014-8611: The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which…
PriorityP433medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.49%
38.8th percentile
The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted application.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | iphone_os | <= 8.4.1 | — |
| apple | mac_os_x | <= 10.10.5 | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| freebsd | freebsd | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-14:27.stdio: Buffer overflow in stdio
bsd_advisories·2014-12-10·CVSS 6.9
CVE-2014-8611 [MEDIUM] FreeBSD-SA-14:27.stdio: Buffer overflow in stdio
FreeBSD-SA-14:27.stdio Security Advisory
The FreeBSD Project
Topic: Buffer overflow in stdio
Category: core
Module: libc
Announced: 2014-12-10
Credits: Adrian Chadd and Alfred Perlstein, Norse Corporation
Affects: FreeBSD 10.1
Corrected: 2014-12-10 08:24:02 UTC (stable/10, 10.1-STABLE)
2014-12-10 08:35:55 UTC (releng/10.1, 10.1-RELEASE-p1)
CVE Name: CVE-2014-8611
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The standard I/O library provides a simple and efficient buffered stream
I/O interface. The library writes buffered data when it is full or when
the application explicitly request so by calling the fflush(3) function.
II. Problem Description
A
Apple
CVE-2014-8611: iOS 9
vendor_apple·CVSS 6.9
CVE-2014-8611 [MEDIUM] CVE-2014-8611: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2014-8611
Component: CVE-ID
Impact: A local user may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.
Apple
CVE-2014-8611: OS X El Capitan v10.11
vendor_apple·CVSS 6.9
CVE-2014-8611 [MEDIUM] CVE-2014-8611: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2014-8611
Component: CVE-ID
Impact: A local user may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.
GHSA
GHSA-23qr-ww7m-6r2f: The __sflush function in fflush
ghsa_unreviewed·2022-05-17
CVE-2014-8611 [MEDIUM] CWE-119 GHSA-23qr-ww7m-6r2f: The __sflush function in fflush
The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttps://support.apple.com/HT205212https://support.apple.com/HT205267https://svnweb.freebsd.org/base?view=revision&revision=275665https://www.freebsd.org/security/advisories/FreeBSD-SA-14:27.stdio.aschttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttps://support.apple.com/HT205212https://support.apple.com/HT205267https://svnweb.freebsd.org/base?view=revision&revision=275665https://www.freebsd.org/security/advisories/FreeBSD-SA-14:27.stdio.asc
2015-09-18
Published