First published: Fri Apr 10 2015(Updated: )
Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.10.2 | |
tvOS | <=7.1 | |
iOS | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1099 is classified as a high severity vulnerability due to its potential to cause denial of service.
To fix CVE-2015-1099, update your Apple iOS to version 8.3 or later, macOS to version 10.10.3 or later, and tvOS to version 7.2 or later.
CVE-2015-1099 affects Apple iOS versions up to 8.2, Mac OS X versions up to 10.10.2, and tvOS versions up to 7.1.
CVE-2015-1099 enables attackers to exploit a race condition, potentially causing a denial of service.
CVE-2015-1099 was disclosed in April 2015.