dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file. Per an <a href"http://support.apple.com/en-us/HT204246">Apple Security Advisory</a> Apple TV before 7.0.3 was also vulnerable.
Per an <a href"http://support.apple.com/en-us/HT204245">Apple Security Advisory</a> Apple iOS before 8.1.3 was also vulnerable.
These product additions are reflected in the vulnerable configuration.
Publication date: Tue, 18 Nov 2014 17:59:00 +0000