CVE Database
/

CVE-2014-8817

Back to search

CVE-2014-8817

Published: Jan 30, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

coresymbolicationd in CoreSymbolication in Apple OS X before 10.10.2 does not verify that expected data types are present in XPC messages, which allows attackers to execute arbitrary code in a privileged context via a crafted app, as demonstrated by lack of verification of xpc_dictionary_get_value API return values during handling of a (1) match_mmap_archives, (2) delete_mmap_archives, (3) write_mmap_archive, or (4) read_mmap_archive command.

VendorProductVersions

n/a

n/a

affected
n/a

References

1031650
vdb-entry
x_refsource_SECTRACK
APPLE-SA-2015-01-27-4
vendor-advisory
x_refsource_APPLE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now