libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2024-08-06T11:20:25.983Z

Reserved: 2014-06-20T00:00:00

Link: CVE-2014-4492

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-01-30T11:59:21.733

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-4492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.