CVE-2015-5907: Low severity iphone os vulnerability
Published Sep 18, 2015
·Updated
WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.
Affected Software
1 affected component
apple iPhone OS<=8.4.1
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5907?
CVE-2015-5907 is considered a high severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2015-5907?
The recommended fix for CVE-2015-5907 is to update to iOS version 9 or later.
3
What types of attacks are possible with CVE-2015-5907?
CVE-2015-5907 allows attackers to conduct redirection attacks by exploiting SSL certificate mishandlings.
4
Which versions of Apple iOS are affected by CVE-2015-5907?
CVE-2015-5907 affects Apple iOS versions prior to 9, specifically up to 8.4.1.
5
Can CVE-2015-5907 impact SSL communications?
Yes, CVE-2015-5907 can compromise SSL communications through the mishandling of the resource cache.