First published: Fri Oct 23 2015(Updated: )
FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5927.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.11.0 | |
Apple iOS, iPadOS, and watchOS | <=2.0.0 | |
iOS | <=9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5942 is considered a critical vulnerability that may allow remote code execution or cause denial of service due to memory corruption.
To fix CVE-2015-5942, update affected versions of iOS, OS X, and watchOS to the latest available versions.
CVE-2015-5942 affects Apple iOS versions prior to 9.1, OS X versions prior to 10.11.1, and watchOS versions prior to 2.0.1.
CVE-2015-5942 enables remote attackers to execute arbitrary code or trigger a denial of service through crafted font files.
Yes, CVE-2015-5942 specifically affects devices running macOS Yosemite, watchOS, and older versions of iPhone OS.