CVE-2015-8659: Buffer Overflow
Published Jan 12, 2016
·Updated
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
Affected Software
5 affected components
Apple iOS and macOS<=10.11.3
nghttp2 nghttp2<=1.5.0
Apple iPhone OS<=9.2.1
Apple tvOS<=9.1
Apple WatchOS<=2.1
Remediation
Patch Available
Event History
Jan 12, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8659?
CVE-2015-8659 is considered to have unspecified severity, potentially allowing exploitation through a heap-use-after-free vulnerability.
2
How do I fix CVE-2015-8659?
To mitigate CVE-2015-8659, upgrade to nghttp2 version 1.6.0 or later, or update affected versions of macOS, iPhone OS, and other Apple operating systems.
3
Which versions of nghttp2 are affected by CVE-2015-8659?
CVE-2015-8659 affects nghttp2 versions prior to 1.6.0, specifically those up to version 1.5.0.
4
Which operating systems are vulnerable to CVE-2015-8659?
CVE-2015-8659 impacts macOS Yosemite, iPhone OS, tvOS, and watchOS up to specific version limits.
5
What type of vulnerability is CVE-2015-8659?
CVE-2015-8659 is categorized as a heap-use-after-free vulnerability, which can lead to unspecified impact.