CVE-2015-5854: Infoleak
Published Oct 9, 2015
·Updated
The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.
Affected Software
1 affected component
Apple iOS and macOS<=10.10.5
Event History
Oct 9, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5854?
CVE-2015-5854 has been rated as potentially high severity due to the risk of unauthorized access to keychain items.
2
How do I fix CVE-2015-5854?
To fix CVE-2015-5854, update to macOS 10.11 or later, where the vulnerability has been addressed.
3
What systems are affected by CVE-2015-5854?
CVE-2015-5854 affects Apple OS X versions prior to 10.11, specifically 10.10.5 and earlier.
4
What kind of access does CVE-2015-5854 allow?
CVE-2015-5854 allows local users to obtain access to sensitive keychain items on the affected systems.
5
Is there a workaround for CVE-2015-5854?
There are no specific workarounds for CVE-2015-5854, the best mitigation is to upgrade to a patched version of macOS.