iOS8.1.1 的安全性更新列表 - iOS

By Elizabeth
at 2014-11-18T09:22
at 2014-11-18T09:22
Table of Contents
值得一提的是
蘋果居然在官方文件的某些漏洞直接@PanguTeam
這次iOS8.1.1的針對性好強啊
=========================================
http://support.apple.com/HT6590
About the security content of iOS 8.1.1
This document describes the security content of iOS 8.1.1.
For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.
For information about the Apple Product Security PGP Key, see How to use the Apple Product Security PGP Key.
Where possible, CVE IDs are used to reference the vulnerabilities for further information.
To learn about other Security Updates, see Apple Security Updates.
iOS 8.1.1
CFNetwork
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: Website cache may not be fully cleared after leaving private browsing
Description: A privacy issue existed where browsing data could remain in the cache after leaving private browsing. This issue was addressed through a change in caching behavior.
CVE-ID
CVE-2014-4460
dyld
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A local user may be able to execute unsigned code
Description: A state management issue existed in the handling of Mach-O executable files with overlapping segments. This issue was addressed through improved validation of segment sizes.
CVE-ID
CVE-2014-4455 : @PanguTeam
Kernel
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A validation issue existed in the handling of certain metadata fields of IOSharedDataQueue objects. This issue was addressed through relocation of the metadata.
CVE-ID
CVE-2014-4461 : @PanguTeam
Lock Screen
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: An attacker in possession of a device may exceed the maximum number of failed passcode attempts
Description: In some circumstances, the failed passcode attempt limit was not enforced. This issue was addressed through additional enforcement of this limit.
CVE-ID
CVE-2014-4451 : Stuart Ryan of University of Technology, Sydney
Lock Screen
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A person with physical access to the phone may be able to access photos in the Photo Library
Description: The Leave a Message option in FaceTime may have allowed viewing and sending photos from the device. This issue was addressed through improved state management.
CVE-ID
CVE-2014-4463
Sandbox Profiles
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A malicious application may be able to launch arbitrary binaries on a trusted device
Description: A permissions issue existed with the debugging functionality for iOS that allowed the spawning of applications on trusted devices that were not being debugged. This was addressed by changes to debugserver's sandbox.
CVE-ID
CVE-2014-4457 : @PanguTeam
Spotlight
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: Unnecessary information is included as part of the initial connection between Spotlight or Safari and the Spotlight Suggestions servers
Description: The initial connection made by Spotlight or Safari to the Spotlight Suggestions servers included a user's approximate location before a user entered a query. This issue was addressed by removing this information from the initial connection and only sending the user's approximate location as part of queries.
CVE-ID
CVE-2014-4453 : Ashkan Soltani
WebKit
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling.
CVE-ID
CVE-2014-4452
CVE-2014-4462
--
--
蘋果居然在官方文件的某些漏洞直接@PanguTeam
這次iOS8.1.1的針對性好強啊
=========================================
http://support.apple.com/HT6590
About the security content of iOS 8.1.1
This document describes the security content of iOS 8.1.1.
For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.
For information about the Apple Product Security PGP Key, see How to use the Apple Product Security PGP Key.
Where possible, CVE IDs are used to reference the vulnerabilities for further information.
To learn about other Security Updates, see Apple Security Updates.
iOS 8.1.1
CFNetwork
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: Website cache may not be fully cleared after leaving private browsing
Description: A privacy issue existed where browsing data could remain in the cache after leaving private browsing. This issue was addressed through a change in caching behavior.
CVE-ID
CVE-2014-4460
dyld
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A local user may be able to execute unsigned code
Description: A state management issue existed in the handling of Mach-O executable files with overlapping segments. This issue was addressed through improved validation of segment sizes.
CVE-ID
CVE-2014-4455 : @PanguTeam
Kernel
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A validation issue existed in the handling of certain metadata fields of IOSharedDataQueue objects. This issue was addressed through relocation of the metadata.
CVE-ID
CVE-2014-4461 : @PanguTeam
Lock Screen
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: An attacker in possession of a device may exceed the maximum number of failed passcode attempts
Description: In some circumstances, the failed passcode attempt limit was not enforced. This issue was addressed through additional enforcement of this limit.
CVE-ID
CVE-2014-4451 : Stuart Ryan of University of Technology, Sydney
Lock Screen
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A person with physical access to the phone may be able to access photos in the Photo Library
Description: The Leave a Message option in FaceTime may have allowed viewing and sending photos from the device. This issue was addressed through improved state management.
CVE-ID
CVE-2014-4463
Sandbox Profiles
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: A malicious application may be able to launch arbitrary binaries on a trusted device
Description: A permissions issue existed with the debugging functionality for iOS that allowed the spawning of applications on trusted devices that were not being debugged. This was addressed by changes to debugserver's sandbox.
CVE-ID
CVE-2014-4457 : @PanguTeam
Spotlight
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: Unnecessary information is included as part of the initial connection between Spotlight or Safari and the Spotlight Suggestions servers
Description: The initial connection made by Spotlight or Safari to the Spotlight Suggestions servers included a user's approximate location before a user entered a query. This issue was addressed by removing this information from the initial connection and only sending the user's approximate location as part of queries.
CVE-ID
CVE-2014-4453 : Ashkan Soltani
WebKit
Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling.
CVE-ID
CVE-2014-4452
CVE-2014-4462
--
推 Zeropapa:你女友是不是鼻子尖尖的10/25 17:44
推 k87559527: 鬍子翹翹的10/25 17:45
噓 LPKing: 手裡還拿根釣竿?10/25 17:46
推 yuanwu:( ′﹀‵)/︴<>< <>< <>< <>< <>< <><10/25 17:49
--
Tags:
iOS
All Comments

By Kristin
at 2014-11-22T02:20
at 2014-11-22T02:20

By Bennie
at 2014-11-23T15:10
at 2014-11-23T15:10

By Genevieve
at 2014-11-25T18:23
at 2014-11-25T18:23

By Kama
at 2014-11-28T11:53
at 2014-11-28T11:53

By Rachel
at 2014-11-30T17:34
at 2014-11-30T17:34

By Olive
at 2014-12-02T03:48
at 2014-12-02T03:48
Related Posts
公眾wifi無法記憶帳密

By Callum
at 2014-11-18T09:18
at 2014-11-18T09:18
Dr.愛瘋 2014.11.18 限時免費軟體報報

By Steve
at 2014-11-18T08:21
at 2014-11-18T08:21
nuPhoto 拍立洗APP 晶鑽寫真本 大放送!

By Aaliyah
at 2014-11-18T07:37
at 2014-11-18T07:37
更新IOS8之後照片變白色

By Rosalind
at 2014-11-18T06:28
at 2014-11-18T06:28
iPad air 主題

By Belly
at 2014-11-18T04:40
at 2014-11-18T04:40