CVE-2015-7079: Input Validation
Published Dec 11, 2015
·Updated
dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
Affected Software
2 affected components
tvOS<=9.0
iPhone OS<=9.1
Event History
Dec 11, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7079?
CVE-2015-7079 has a high severity rating due to its potential to allow attackers to execute arbitrary code in a privileged context.
2
How do I fix CVE-2015-7079?
To fix CVE-2015-7079, update your Apple iOS to version 9.2 or later, or your tvOS to version 9.1 or later.
3
What systems are affected by CVE-2015-7079?
CVE-2015-7079 affects Apple iOS versions before 9.2 and tvOS versions before 9.1.
4
What kind of attack does CVE-2015-7079 enable?
CVE-2015-7079 enables attackers to execute arbitrary code by exploiting mishandled segment validation in dyld.
5
Is there any workaround for CVE-2015-7079?
There are no official workarounds for CVE-2015-7079; updating your software is the recommended mitigation.