CVE-2014-8838
published 2015-01-30CVE-2014-8838: The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.85%
54.7th percentile
The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate for signing a crafted app.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.1 | — |
| apple | os_x_yosemite_v10.10.2_and_security_update_2015-001 | — | — |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.16 | 5.5.9+dfsg-1ubuntu4.16 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2014-8838: OS X Yosemite v10.10.2 and Security Update 2015-001
vendor_apple·CVSS 4.3
CVE-2014-8838 [MEDIUM] CVE-2014-8838: OS X Yosemite v10.10.2 and Security Update 2015-001
Apple Security Update: About the security content of OS X Yosemite v10.10.2 and Security Update 2015-001
Product: OS X Yosemite v10.10.2 and Security Update 2015-001
CVE: CVE-2014-8838
Component: CVE-ID
Impact: An app may access keychain items belonging to other apps
Description: An access control issue existed in the Keychain. Applications signed with self-signed or Developer ID certificates could access keychain items whose access control lists were based on keychain groups. This issue was addressed by validating the signing identity when granting access to keychain groups.
GHSA
GHSA-74x2-6767-r88g: The Security component in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2014-8838 [MEDIUM] GHSA-74x2-6767-r88g: The Security component in Apple OS X before 10
The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate for signing a crafted app.
OSV
php5 vulnerabilities
osv·2016-04-21·CVSS 4.3
CVE-2014-9767 php5 vulnerabilities
php5 vulnerabilities
It was discovered that the PHP Zip extension incorrectly handled
directories when processing certain zip files. A remote attacker could
possibly use this issue to create arbitrary directories. (CVE-2014-9767)
It was discovered that the PHP Soap client incorrectly validated data
types. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-8835, CVE-2016-3185)
It was discovered that the PHP MySQL native driver incorrectly handled TLS
connections to MySQL databases. A machine-in-the-middle attacker could possibly
use this issue to downgrade and snoop on TLS connections. This
vulnerability is known as BACKRONYM. (CVE-2015-8838)
It was discovered that PHP incorrectly handled the imag
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlhttp://support.apple.com/HT204244http://www.securitytracker.com/id/1031650https://exchange.xforce.ibmcloud.com/vulnerabilities/100525http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlhttp://support.apple.com/HT204244http://www.securitytracker.com/id/1031650https://exchange.xforce.ibmcloud.com/vulnerabilities/100525
2015-01-30
Published