CVE-2015-1104: Input Validation
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local origin, which allows remote attackers to bypass an intended network-filtering protection mechanism via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1104?
CVE-2015-1104 is considered a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2015-1104?
To mitigate the risk of CVE-2015-1104, users should update their devices to iOS 8.3, OS X 10.10.3, or tvOS 7.2 or later.
What systems are affected by CVE-2015-1104?
CVE-2015-1104 affects Apple iOS versions prior to 8.3, OS X versions prior to 10.10.3, and tvOS versions prior to 7.2.
What kind of attack does CVE-2015-1104 enable?
CVE-2015-1104 allows remote attackers to bypass network-filtering mechanisms through crafted IPv6 packets.
Is there a workaround for CVE-2015-1104?
There are no specific workarounds for CVE-2015-1104, and updating to the latest software is recommended for full protection.