First published: Sun Aug 16 2015(Updated: )
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iOS | <=8.4 | |
Apple iOS and macOS | <=10.10.4 | |
iOS | <=9.1 | |
Apple iOS and macOS | <=10.11.1 | |
tvOS | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3807 is classified as a high-severity vulnerability due to its potential to cause denial of service and information disclosure.
CVE-2015-3807 affects iOS versions prior to 8.4.1.
CVE-2015-3807 impacts OS X versions before 10.10.5.
To mitigate CVE-2015-3807, update your Apple device to the latest available versions of iOS or OS X that address this vulnerability.
CVE-2015-3807 can be exploited through crafted XML documents that lead to memory corruption or information leakage.