First published: Fri Sep 18 2015(Updated: )
The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.10.5 | |
iStyle @cosme iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5912 has been classified as a medium severity vulnerability.
CVE-2015-5912 allows remote FTP proxy servers to cause TCP connection attempts to intranet hosts, potentially leading to unauthorized access.
CVE-2015-5912 affects Apple iOS before version 9 and macOS Yosemite up to version 10.10.5.
To mitigate CVE-2015-5912, update your device to the latest version of iOS or macOS that addresses this vulnerability.
Yes, Apple has released updates that address the vulnerabilities associated with CVE-2015-5912.