CVE-2015-5842: Infoleak
Published Sep 18, 2015
·Updated
XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.
Affected Software
3 affected components
Apple iPhone OS<=8.4.1
Apple WatchOS=1.0
Apple iOS and macOS<=10.10.5
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5842?
CVE-2015-5842 is considered a medium severity vulnerability due to its potential to expose sensitive memory-layout information.
2
How do I fix CVE-2015-5842?
To mitigate CVE-2015-5842, users should update their Apple device to the latest version of iOS, watchOS, or macOS.
3
What type of systems are affected by CVE-2015-5842?
CVE-2015-5842 affects iOS prior to 9, watchOS 1.0, and macOS Yosemite up to 10.10.5.
4
Who can exploit CVE-2015-5842?
CVE-2015-5842 can be exploited by local users who have access to the affected systems.
5
What are the potential consequences of CVE-2015-5842?
Exploitation of CVE-2015-5842 could lead to unauthorized access to sensitive memory layout information.