CVE-2015-5879: Input Validation
Published Sep 18, 2015
·Updated
XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-number protection mechanism and cause a denial of service (TCP connection disruption) via a crafted header.
Affected Software
2 affected components
Apple iPhone OS<=8.4.1
Apple iOS and macOS<=10.10.5
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5879?
CVE-2015-5879 has a moderate severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2015-5879?
To fix CVE-2015-5879, update to a secure version of iOS 9 or later, or macOS 10.11 or later.
3
What systems are affected by CVE-2015-5879?
CVE-2015-5879 affects Apple iOS versions below 9 and macOS Yosemite versions below 10.11.
4
What does CVE-2015-5879 exploit in Apple systems?
CVE-2015-5879 exploits improper validation of TCP packet headers, allowing sequence-number protection bypass.
5
What impact does CVE-2015-5879 have on users?
CVE-2015-5879 can lead to disrupted TCP connections, causing user-facing denial of service.