First published: Fri Jan 11 2019(Updated: )
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Apple Tv | <9.2.2 | |
Apple iPhone OS | <9.3.3 | |
Apple macOS | >=10.11.0<10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4642 is a vulnerability that affects iOS, tvOS, and OS X El Capitan before v10.11.6.
CVE-2016-4642 allows proxy authentication to incorrectly report HTTP proxies received credentials securely, which may lead to unauthorized access.
CVE-2016-4642 has a severity rating of 5.9 (medium).
To fix CVE-2016-4642, update to iOS 9.3.3, tvOS 9.2.2, or OS X El Capitan v10.11.6 or later.
You can find more information about CVE-2016-4642 on the Apple Support website: [link](https://support.apple.com/HT206902), [link](https://support.apple.com/HT206903), [link](https://support.apple.com/HT206905).