CVE-2015-1103: Input Validation
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMPREDIRECT messages, which allows remote attackers to cause a denial of service (network outage) or obtain sensitive packet-content information via a crafted ICMP packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1103?
CVE-2015-1103 has been classified as a high severity vulnerability due to its potential to cause network outages.
How do I fix CVE-2015-1103?
To mitigate CVE-2015-1103, users should update their devices to iOS version 8.3, OS X version 10.10.3, or tvOS version 7.2 or later.
What types of devices are affected by CVE-2015-1103?
CVE-2015-1103 affects iPhones running iOS before 8.3, Mac computers with OS X before 10.10.3, and Apple TVs prior to version 7.2.
What attacks can be executed using CVE-2015-1103?
Exploiting CVE-2015-1103 allows attackers to cause denial of service conditions or gain access to sensitive packet content through crafted ICMP packets.
Is CVE-2015-1103 still a risk for current Apple devices?
CVE-2015-1103 is not a risk for devices running the patched versions that are currently supported by Apple.