CVE-2015-1062: Medium severity tvos vulnerability
Published Mar 12, 2015
·Updated
MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app.
Affected Software
2 affected components
tvOS<=7.0.3
iPhone OS<=8.1.3
Event History
Mar 12, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1062?
CVE-2015-1062 has a moderate severity level as it allows attackers to create folders in arbitrary filesystem locations.
2
How do I fix CVE-2015-1062?
To mitigate CVE-2015-1062, update to Apple iOS version 8.2 or later and tvOS version 7.1 or later.
3
Which devices are affected by CVE-2015-1062?
CVE-2015-1062 affects Apple iOS versions before 8.2 and Apple TV versions before 7.1.
4
What could an attacker do with CVE-2015-1062?
An attacker exploiting CVE-2015-1062 could create folders in unauthorized filesystem locations via a malicious app.
5
Is there a workaround for CVE-2015-1062?
There are no documented workarounds for CVE-2015-1062; the recommended action is to upgrade the affected software.