PT-2015-1878 · Apple · Ios
Cererdlong
·
Published
2015-08-16
·
Updated
2016-12-24
·
CVE-2015-3759
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 8.4.1
Description
The issue is related to the Location Framework component in the iOS operating system, which has inadequate access control restrictions. This allows a local attacker to bypass existing access restrictions to filesystem objects using symbolic links.
Recommendations
For versions prior to 8.4.1, update to version 8.4.1 or later to resolve the issue.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ios