First published: Fri Apr 10 2015(Updated: )
NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <=7.1 | |
Apple iPhone OS | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1092 is considered a high severity vulnerability due to its potential for remote attackers to exploit XML External Entity (XXE) processing.
To mitigate CVE-2015-1092, users should upgrade to Apple iOS version 8.3 or later, or tvOS version 7.2 or later.
The exploitation of CVE-2015-1092 could allow remote attackers to read arbitrary files on the device.
CVE-2015-1092 affects Apple iOS versions prior to 8.3 and Apple TV versions prior to 7.2.
CVE-2015-1092 is classified as an XML External Entity (XXE) vulnerability.