CVE-2015-5841: Medium severity apple ios and macos vulnerability
The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5841?
CVE-2015-5841 is considered a high severity vulnerability due to the potential for cookie-injection attacks.
How do I fix CVE-2015-5841?
The best fix for CVE-2015-5841 involves updating your Apple device to the latest available version of the affected OS.
Which versions of software are affected by CVE-2015-5841?
CVE-2015-5841 affects Apple iOS versions prior to 8.4.2, OS X Yosemite up to and including 10.10.5, and watchOS 1.0.
What kinds of attacks can be executed through CVE-2015-5841?
CVE-2015-5841 can allow remote proxy servers to execute cookie-injection attacks through crafted HTTP responses.
Is there a workaround for CVE-2015-5841 while waiting for a fix?
A possible workaround for CVE-2015-5841 includes avoiding the use of potentially malicious proxy servers.