CVE-2014-4494
N/A
N/A
Summary
Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-launch restrictions by leveraging access to an enterprise distribution certificate for signing a crafted app.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://support.apple.com/HT204245
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
- http://www.securitytracker.com/id/1031652
References
- http://support.apple.com/HT204245
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html
- http://www.securitytracker.com/id/1031652
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.