First published: Tue Jan 12 2016(Updated: )
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | <=10.11.3 | |
libnghttp2-14 | <=1.5.0 | |
iStyle @cosme iPhone OS | <=9.2.1 | |
tvOS | <=9.1 | |
Apple iOS, iPadOS, and watchOS | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8659 is considered to have unspecified severity, potentially allowing exploitation through a heap-use-after-free vulnerability.
To mitigate CVE-2015-8659, upgrade to nghttp2 version 1.6.0 or later, or update affected versions of macOS, iPhone OS, and other Apple operating systems.
CVE-2015-8659 affects nghttp2 versions prior to 1.6.0, specifically those up to version 1.5.0.
CVE-2015-8659 impacts macOS Yosemite, iPhone OS, tvOS, and watchOS up to specific version limits.
CVE-2015-8659 is categorized as a heap-use-after-free vulnerability, which can lead to unspecified impact.