CVE-2015-1099Race Condition in Apple Iphone OS

CWE-362Race Condition6 documents3 sources
Severity
4.0MEDIUMNVD
EPSS
0.1%
top 77.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 14

Description

Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.

CVSS vector

AV:L/AC:H/C:N/I:N/A:CExploitability: 1.9 | Impact: 6.9

Affected Packages7 packages

NVDapple/tvos7.1
NVDapple/mac_os_x10.10.2
Appleapple/ios8.3
Appleapple/apple_tv7.2

🔴Vulnerability Details

1
GHSA
GHSA-2g83-93g3-qr66: Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 82022-05-14

📋Vendor Advisories

4
Apple
CVE-2015-1099: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple
CVE-2015-1099: Watch OS 1.0.1
Apple
CVE-2015-1099: iOS 8.3
Apple
CVE-2015-1099: Apple TV 7.2