CVE-2015-1105: Input Validation
The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urgent (aka out-of-band data) mechanism, which allows remote attackers to cause a denial of service via crafted packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1105?
CVE-2015-1105 has a moderate severity rating as it can lead to denial of service attacks.
How do I fix CVE-2015-1105?
To mitigate CVE-2015-1105, update your Apple iOS, OS X, or tvOS to the latest version available beyond the vulnerable versions.
What products are impacted by CVE-2015-1105?
CVE-2015-1105 affects Apple iOS versions prior to 8.3, OS X versions prior to 10.10.3, and tvOS versions prior to 7.2.
Can CVE-2015-1105 be exploited remotely?
Yes, CVE-2015-1105 can be exploited remotely by sending specially crafted TCP packets.
What is the underlying issue in CVE-2015-1105?
CVE-2015-1105 is caused by an improper implementation of the Urgent (out-of-band data) mechanism in the TCP protocol.