First published: Fri Sep 18 2015(Updated: )
WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iPhone OS | <=8.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5921 is classified as a medium severity vulnerability due to its potential for information disclosure through man-in-the-middle attacks.
To mitigate CVE-2015-5921, update to the latest version of iOS that addresses this vulnerability.
CVE-2015-5921 affects Apple iOS versions before 9, including version 8.4.1 and earlier.
CVE-2015-5921 can be exploited by man-in-the-middle attackers to obtain sensitive information.
CVE-2015-5921 specifically affects the handling of "Content-Disposition: attachment" HTTP headers in WebKit.