CVE-2015-3804: Buffer Overflow
Published Aug 16, 2015
·Updated
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5756 and CVE-2015-5775.
Affected Software
2 affected components
Apple iOS and macOS<=10.10.4
Apple iPhone OS<=8.4
Event History
Aug 16, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3804?
CVE-2015-3804 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2015-3804?
To fix CVE-2015-3804, update your Apple iOS to version 8.4.1 or later and macOS to version 10.10.5 or later.
3
What types of attacks does CVE-2015-3804 facilitate?
CVE-2015-3804 can facilitate remote code execution or cause a denial of service through crafted font files.
4
Which versions of macOS are affected by CVE-2015-3804?
CVE-2015-3804 affects macOS versions prior to 10.10.5.
5
Which versions of iOS are affected by CVE-2015-3804?
CVE-2015-3804 affects iOS versions prior to 8.4.1.