CVE-2015-5921: Infoleak
Published Sep 18, 2015
·Updated
WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
apple iPhone OS<=8.4.1
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5921?
CVE-2015-5921 is classified as a medium severity vulnerability due to its potential for information disclosure through man-in-the-middle attacks.
2
How do I fix CVE-2015-5921?
To mitigate CVE-2015-5921, update to the latest version of iOS that addresses this vulnerability.
3
What versions of iOS are affected by CVE-2015-5921?
CVE-2015-5921 affects Apple iOS versions before 9, including version 8.4.1 and earlier.
4
What type of attacks can exploit CVE-2015-5921?
CVE-2015-5921 can be exploited by man-in-the-middle attackers to obtain sensitive information.
5
What does CVE-2015-5921 affect in WebKit?
CVE-2015-5921 specifically affects the handling of "Content-Disposition: attachment" HTTP headers in WebKit.