CVE-2015-1124: Medium severity itunes vulnerability
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1124?
CVE-2015-1124 is classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2015-1124?
To mitigate CVE-2015-1124, update to the latest version of affected software, including iOS 8.3 or later, Safari 8.0.5 or later, and relevant updates for Apple TV.
What types of attacks are possible using CVE-2015-1124?
CVE-2015-1124 can be exploited to execute arbitrary code or cause a denial of service due to memory corruption.
Which Apple products are impacted by CVE-2015-1124?
CVE-2015-1124 affects Apple iTunes prior to 12.1, Apple iOS before 8.3, tvOS before 7.1, and multiple versions of Safari.
What should I do if I cannot update to fix CVE-2015-1124?
If you cannot update, consider using alternative browsers or limiting your device's exposure to untrusted websites to reduce the risk associated with CVE-2015-1124.