iOS8.1.1 的安全性更新列表 - iOS

Elizabeth avatar
By Elizabeth
at 2014-11-18T09:22

Table of Contents

值得一提的是
蘋果居然在官方文件的某些漏洞直接@PanguTeam
這次iOS8.1.1的針對性好強啊

=========================================

http://support.apple.com/HT6590


About the security content of iOS 8.1.1
This document describes the security content of iOS 8.1.1.

For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see How to use the Apple Product Security PGP Key.

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To learn about other Security Updates, see Apple Security Updates.

iOS 8.1.1
CFNetwork

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: Website cache may not be fully cleared after leaving private browsing

Description: A privacy issue existed where browsing data could remain in the cache after leaving private browsing. This issue was addressed through a change in caching behavior.

CVE-ID

CVE-2014-4460

dyld

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: A local user may be able to execute unsigned code

Description: A state management issue existed in the handling of Mach-O executable files with overlapping segments. This issue was addressed through improved validation of segment sizes.

CVE-ID

CVE-2014-4455 : @PanguTeam

Kernel

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: A malicious application may be able to execute arbitrary code with system privileges

Description: A validation issue existed in the handling of certain metadata fields of IOSharedDataQueue objects. This issue was addressed through relocation of the metadata.

CVE-ID

CVE-2014-4461 : @PanguTeam

Lock Screen

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: An attacker in possession of a device may exceed the maximum number of failed passcode attempts

Description: In some circumstances, the failed passcode attempt limit was not enforced. This issue was addressed through additional enforcement of this limit.

CVE-ID

CVE-2014-4451 : Stuart Ryan of University of Technology, Sydney

Lock Screen

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: A person with physical access to the phone may be able to access photos in the Photo Library

Description: The Leave a Message option in FaceTime may have allowed viewing and sending photos from the device. This issue was addressed through improved state management.

CVE-ID

CVE-2014-4463

Sandbox Profiles

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: A malicious application may be able to launch arbitrary binaries on a trusted device

Description: A permissions issue existed with the debugging functionality for iOS that allowed the spawning of applications on trusted devices that were not being debugged. This was addressed by changes to debugserver's sandbox.

CVE-ID

CVE-2014-4457 : @PanguTeam

Spotlight

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: Unnecessary information is included as part of the initial connection between Spotlight or Safari and the Spotlight Suggestions servers

Description: The initial connection made by Spotlight or Safari to the Spotlight Suggestions servers included a user's approximate location before a user entered a query. This issue was addressed by removing this information from the initial connection and only sending the user's approximate location as part of queries.

CVE-ID

CVE-2014-4453 : Ashkan Soltani

WebKit

Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later

Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling.

CVE-ID

CVE-2014-4452

CVE-2014-4462

--
Zeropapa:你女友是不是鼻子尖尖的10/25 17:44
k87559527: 鬍子翹翹的10/25 17:45
LPKing: 手裡還拿根釣竿?10/25 17:46
yuanwu:( ′﹀‵)/︴<>< <>< <>< <>< <>< <><10/25 17:49

--
Tags: iOS

All Comments

Kristin avatar
By Kristin
at 2014-11-22T02:20
你女友是不是鼻子尖尖的
Bennie avatar
By Bennie
at 2014-11-23T15:10
鬍子翹翹的
Genevieve avatar
By Genevieve
at 2014-11-25T18:23
手裡還拿根釣竿?
Kama avatar
By Kama
at 2014-11-28T11:53
( ′﹀‵)/︴<>< <>< <>< <>< <>< <><
Rachel avatar
By Rachel
at 2014-11-30T17:34
業界原則都是這樣,要給發現漏洞的人 credit
Olive avatar
By Olive
at 2014-12-02T03:48
上次好像也有 @evad3rs 啊

公眾wifi無法記憶帳密

Callum avatar
By Callum
at 2014-11-18T09:18
公眾wifi如:iTaiwan、7-wifi等可以免費上網, 需要登入帳號密碼,通常可以勾選記憶帳密, 但我每次勾選登入,下次要再使用都得再輸入一次, 以前 ios 還是7.1.2時沒這問題,升到8只後才這樣 已經有把 safari 的記憶密碼功能打開。 不知道這問題現在要怎麼解決...? - ...

Dr.愛瘋 2014.11.18 限時免費軟體報報

Steve avatar
By Steve
at 2014-11-18T08:21
Dr.愛瘋 2014.11.18 限時免費軟體報報 完整圖文來源連結:http://app.yipee.cc/61136/ 加入我們的粉絲頁,看最新消息:https://www.facebook.com/Dr.iPhone.Fans ------------------------------------- ...

nuPhoto 拍立洗APP 晶鑽寫真本 大放送!

Aaliyah avatar
By Aaliyah
at 2014-11-18T07:37
軟體名稱:nuPhoto拍立洗 質感沖洗 APP 軟體分類:攝影 軟體連結:https://itunes.apple.com/tw/app/nuphoto-pai-li-xi-xi-chu-chao/id5847 87808?mt=8 縮網址: http://goo.gl/4LbwUD ...

更新IOS8之後照片變白色

Rosalind avatar
By Rosalind
at 2014-11-18T06:28
剛剛更新IOS8.1之後 相機膠捲裡面的照片有些都變白色不能看 點下去只會出現載入中... 有人遇到跟我一樣的問題嗎? 不知道有沒有辦法解決 麻煩各位幫忙 - ...

iPad air 主題

Belly avatar
By Belly
at 2014-11-18T04:40
有點久沒JB了,上次的JB還停留在iOS5.1.1的iPhone4 XDD 剛剛把iPad air JB了 可是有一個我發現跟之前不一樣的點就是cydia裡的主題 我只有看到精選主題欸...我記得以前可以找很多種阿 還有免費的可以找,還是iOS8之後就沒有免費的主題了阿... 感覺問題有點蠢可是我 ...