The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted application that is run during a time period when debugging is not enabled.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2014/Nov/msg00000.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98777 | vdb entry |
https://support.apple.com/en-us/HT6590 | vendor advisory |
http://www.securityfocus.com/bid/71143 | vdb entry |
http://www.securitytracker.com/id/1031232 | vdb entry |
https://support.apple.com/en-us/HT204418 |