PT-2015-2137 · Apple+2 · Webkit+3

Publicado

2015-09-18

·

Atualizado

2024-06-15

·

CVE-2015-5788

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iOS versions prior to 9
Description The issue is related to the WebKit Canvas implementation, which lacks protection of service data. This can be exploited by a remote attacker to bypass the Same Origin Policy and gain access to sensitive information by manipulating the domain restriction rules. The exploitation involves using a CANVAS element to obtain sensitive image information.
Recommendations For Apple iOS versions prior to 9, update to version 9 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebKit Canvas implementation until a patch is available. Avoid using the CANVAS element in sensitive operations until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1245
ALT-PU-2016-1315
BDU:2015-11483
CVE-2015-5788
MGASA-2016-0116
MGASA-2016-0120
OPENSUSE-SU-2024:10461-1
USN-2937-1

Produtos afetados

Alt Linux
Ubuntu
Webkit
Ios