CVE-2015-3805: Input Validation
Published Aug 16, 2015
·Updated
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.
Affected Software
2 affected components
Apple iPhone OS<=8.4
Apple iOS and macOS<=10.10.4
Event History
Aug 16, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3805?
CVE-2015-3805 has been classified with a moderate severity level due to its ability to allow code-signing protection bypass for local users.
2
How do I fix CVE-2015-3805?
To fix CVE-2015-3805, users should update to iOS version 8.4.1 or later and OS X version 10.10.5 or later.
3
What systems are affected by CVE-2015-3805?
CVE-2015-3805 affects Apple iOS versions prior to 8.4.1 and OS X versions prior to 10.10.5.
4
Who is vulnerable to CVE-2015-3805?
Local users on affected Apple devices are vulnerable to the exploit described in CVE-2015-3805.
5
What type of attack does CVE-2015-3805 facilitate?
CVE-2015-3805 facilitates a code-signing protection bypass via the use of a crafted Mach-O file.