CVE-2014-1354

iPhone OS < 7.1.2 - Remote Code Execution via XBM Image Processing

Title source: llm
STIX 2.1

Description

CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68276
Third Party Advisory vendor-advisory x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030500

Scores

EPSS 0.0285
EPSS Percentile 85.2%

Details

CWE
CWE-399
Status published
Products (9)
apple/iphone_os 7.0
apple/iphone_os 7.0.1
apple/iphone_os 7.0.2
apple/iphone_os 7.0.3
apple/iphone_os 7.0.4
apple/iphone_os 7.0.5
apple/iphone_os 7.0.6
apple/iphone_os 7.1
apple/iphone_os < 7.1.1
Published Jul 01, 2014
Tracked Since Feb 18, 2026