Vulnerability CVE-2015-1100


Published: 2015-04-10

Description:
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Mac OS X 10.10.2 Local Denial of Service
Maxime Villard
22.04.2015

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:L/AC:M/Au:N/C:P/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.4/10
7.8/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
Complete
Affected software
Apple -> Apple tv 
Apple -> Iphone os 
Apple -> Mac os x 
Apple -> TVOS 

 References:
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html
http://lists.apple.com/archives/security-announce/2015/Apr/msg00003.html
http://m00nbsd.net/garbage/Mac-OS-X_Fat-DoS.txt
http://www.securitytracker.com/id/1032048
https://support.apple.com/HT204659
https://support.apple.com/HT204661
https://support.apple.com/HT204662
https://support.apple.com/kb/HT204870
https://www.exploit-db.com/exploits/36814/

Copyright 2024, cxsecurity.com

 

Back to Top