CVE-2015-3027: Medium severity apple xcode vulnerability
Published Apr 10, 2015
·Updated
Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers to bypass a stack-guard protection mechanism via crafted input to an affected C program.
Affected Software
1 affected component
Apple Xcode<=6.2
Event History
Apr 10, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3027?
CVE-2015-3027 is categorized as a medium severity vulnerability due to the potential for stack cookie bypass.
2
How do I fix CVE-2015-3027?
To fix CVE-2015-3027, update Apple Xcode to version 6.3 or later.
3
What versions of Xcode are affected by CVE-2015-3027?
Xcode versions up to and including 6.2 are affected by CVE-2015-3027.
4
What type of attack does CVE-2015-3027 enable?
CVE-2015-3027 enables context-dependent attackers to bypass stack-guard protections.
5
What components are impacted by CVE-2015-3027?
CVE-2015-3027 impacts the Clang compiler in LLVM as used within Apple Xcode.