dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.
Monthly Archives: November 2014
CVE-2014-4457 (iphone_os)
The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted application that is run during a time period when debugging is not enabled.
CVE-2014-4458 (mac_os_x)
The “System Profiler About This Mac” component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2014-4459 (mac_os_x)
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
CVE-2014-4460 (iphone_os, mac_os_x)
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
CVE-2014-4461 (apple_tv, iphone_os)
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
CVE-2014-4462 (apple_tv, iphone_os)
WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4452.
CVE-2014-4463 (iphone_os)
Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or transmit a Photo Library photo, via the FaceTime “Leave a Message” feature.
Fedora 19 Security Update: python-django14-1.4.16-1.fc19
Resolved Bugs
1132774 – CVE-2014-0480 CVE-2014-0481 CVE-2014-0482 CVE-2014-0483 python-django14: various flaws [fedora-all]
1129950 – CVE-2014-0480 Django: reverse() can generate URLs pointing to other hosts, leading to phishing attacks
1129952 – CVE-2014-0481 Django: file upload denial of service
1129954 – CVE-2014-0482 Django: RemoteUserMiddleware session hijacking
1129959 – CVE-2014-0483 Django: data leakage via querystring manipulation in admin<br
Update to latest stable release
Fedora 21 Security Update: wireshark-1.12.2-1.fc21
Ver. 1.12.2, Security fix for CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714, CVE-2014-8710