CVE-2015-3806: High severity iphone os vulnerability
Published Aug 16, 2015
·Updated
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.
Affected Software
2 affected components
Apple iPhone OS<=8.4
Apple iOS and macOS<=10.10.4
Event History
Aug 16, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3806?
CVE-2015-3806 has a medium severity rating due to its potential for exploitation by local users.
2
How do I fix CVE-2015-3806?
To fix CVE-2015-3806, update your iOS devices to version 8.4.1 or higher, and your macOS to version 10.10.5 or higher.
3
What systems are affected by CVE-2015-3806?
CVE-2015-3806 affects Apple iOS versions before 8.4.1 and macOS versions before 10.10.5.
4
Can local users exploit CVE-2015-3806?
Yes, local users can exploit CVE-2015-3806 to bypass code-signing protections on affected systems.
5
What type of vulnerability is CVE-2015-3806?
CVE-2015-3806 is a code-signing bypass vulnerability that affects file execution security.