First published: Sun Aug 16 2015(Updated: )
Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.10.4 | |
iOS | <=8.4 | |
Apple Numbers | <=3.5 | |
Apple Keynote | <=6.5 | |
Apple Pages | <=5.5.3 | |
Apple iWork | <=2.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3784 is considered a moderate severity vulnerability due to its potential impact on user data privacy.
To fix CVE-2015-3784, users should update to Apple iOS version 8.4.1 or later and OS X version 10.10.5 or later.
CVE-2015-3784 affects Apple iOS, OS X, and specific applications such as Apple Numbers, Keynote, and Pages.
CVE-2015-3784 allows remote attackers to read arbitrary files through an XML External Entity (XXE) vulnerability.
CVE-2015-3784 was disclosed in August 2015 as part of a security announcement from Apple.