First published: Fri Apr 10 2015(Updated: )
The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urgent (aka out-of-band data) mechanism, which allows remote attackers to cause a denial of service via crafted packets.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.10.2 | |
iPhone OS | <=8.2 | |
tvOS | <=7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1105 has a moderate severity rating as it can lead to denial of service attacks.
To mitigate CVE-2015-1105, update your Apple iOS, OS X, or tvOS to the latest version available beyond the vulnerable versions.
CVE-2015-1105 affects Apple iOS versions prior to 8.3, OS X versions prior to 10.10.3, and tvOS versions prior to 7.2.
Yes, CVE-2015-1105 can be exploited remotely by sending specially crafted TCP packets.
CVE-2015-1105 is caused by an improper implementation of the Urgent (out-of-band data) mechanism in the TCP protocol.