CVE-2015-1126: Input Validation
Published Apr 10, 2015
·Updated
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.
Affected Software
19 affected components
iPhone OS<=8.2
Safari<=6.2.4
Safari=7.0
Safari=7.0.1
Safari=7.0.2
Safari=7.0.3
Safari=7.0.4
Safari=7.0.5
Safari=7.0.6
Safari=7.1.0
Safari=7.1.1
Safari=7.1.2
Safari=7.1.3
Safari=7.1.4
Safari=8.0.0
Safari=8.0.1
Safari=8.0.2
Safari=8.0.3
Safari=8.0.4
Event History
Apr 10, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1126?
CVE-2015-1126 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-1126?
To fix CVE-2015-1126, update affected software to the latest versions provided by Apple.
3
Which software is affected by CVE-2015-1126?
CVE-2015-1126 affects Apple iOS versions before 8.3 and Safari versions before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5.
4
What kind of attack does CVE-2015-1126 allow?
CVE-2015-1126 allows remote attackers to trigger incorrect resource access through FTP URLs.
5
When was CVE-2015-1126 reported?
CVE-2015-1126 was reported in April 2015.