First published: Fri Jul 03 2015(Updated: )
The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-3677 is rated as moderate due to its potential to expose sensitive memory layout information.
To fix CVE-2015-3677, update your macOS to version 10.10.4 or later.
CVE-2015-3677 affects macOS versions prior to 10.10.4.
CVE-2015-3677 could be exploited by attackers through a crafted application to gather sensitive information.
There are no documented workarounds for mitigating CVE-2015-3677; updating the operating system is recommended.