PT-2015-1877 · Apple · Uikit Webview+2

Brian Simmons

+1

·

Publicado

2015-08-16

·

Atualizado

2016-12-24

·

CVE-2015-3758

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 8.4.1
Description The issue exists due to insufficient input validation in the UIKit WebView component of the iOS operating system. This allows a remote attacker to initiate arbitrary FaceTime calls using a specially crafted URL, bypassing the intended user-confirmation requirement.
Recommendations For iOS versions prior to 8.4.1, update to version 8.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to FaceTime or avoiding the use of specially crafted URLs in the affected UIKit WebView component until the issue is resolved.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11223
CVE-2015-3758

Produtos afetados

Facetime
Uikit Webview
Ios