CVE-2015-1157
published 2015-05-28CVE-2015-1157: CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
5.55%
92.0th percentile
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | itunes | <= 12.2 | — |
| apple | itunes | — | — |
| apple | mac_os_x | <= 10.0.3 | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-3689: iOS 8.4
vendor_apple·CVSS 7.8
CVE-2015-3689 [HIGH] CVE-2015-3689: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3689
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3686: iOS 8.4
vendor_apple·CVSS 7.8
CVE-2015-3686 [HIGH] CVE-2015-3686: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3686
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-1157: iOS 8.4
vendor_apple·CVSS 7.8
CVE-2015-1157 [HIGH] CVE-2015-1157: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-1157
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-1157: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.8
CVE-2015-1157 [HIGH] CVE-2015-1157: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-1157
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3688: iOS 8.4
vendor_apple·CVSS 7.8
CVE-2015-3688 [HIGH] CVE-2015-3688: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3688
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3687: iOS 8.4
vendor_apple·CVSS 7.8
CVE-2015-3687 [HIGH] CVE-2015-3687: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3687
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3686: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.8
CVE-2015-3686 [HIGH] CVE-2015-3686: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-3686
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3685: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.8
CVE-2015-3685 [HIGH] CVE-2015-3685: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-3685
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3689: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.8
CVE-2015-3689 [HIGH] CVE-2015-3689: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-3689
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-1157: iTunes 12.3
vendor_apple·CVSS 7.8
CVE-2015-1157 [HIGH] CVE-2015-1157: iTunes 12.3
Apple Security Update: About the security content of iTunes 12.3
Product: iTunes
Version: 12.3
CVE: CVE-2015-1157
Component: CVE-ID
Impact: Applications that use ICU may be vulnerable to unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in the processing of unicode strings. These issues were addressed by updating ICU to version 55.
Apple
CVE-2015-3688: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.8
CVE-2015-3688 [HIGH] CVE-2015-3688: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-3688
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3685: iOS 8.4
vendor_apple·CVSS 7.8
CVE-2015-3685 [HIGH] CVE-2015-3685: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3685
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
Apple
CVE-2015-3687: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.8
CVE-2015-3687 [HIGH] CVE-2015-3687: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-3687
Component: CVE-2015-1157
Impact: An attacker with a privileged network position may intercept SSL/TLS connections
Description: coreTLS accepted short ephemeral Diffie-Hellman (DH) keys, as used in export-strength ephemeral DH cipher suites. This issue, also known as Logjam, allowed an attacker with a privileged network position to downgrade security to 512-bit DH if the server supported an export-strength ephemeral DH cipher suite. The issue was addressed by increasing the default minimum size allowed for DH ephemeral keys to 768 bits.
GHSA
GHSA-r4wc-44ww-v8f2: CoreText in Apple iOS 8
ghsa_unreviewed·2022-05-17
CVE-2015-1157 [HIGH] GHSA-r4wc-44ww-v8f2: CoreText in Apple iOS 8
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://9to5mac.com/2015/05/27/how-to-fix-ios-text-message-bug-crash-reboot/http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.ibtimes.co.uk/apple-ios-bug-sees-message-app-crash-iphone-reboot-simply-by-receiving-message-1503083http://www.reddit.com/r/apple/comments/37e8c1/malicious_text_message/http://www.reddit.com/r/apple/comments/37enow/about_the_latest_iphone_security_vulnerability/http://www.reddit.com/r/explainlikeimfive/comments/37edde/eli5_how_that_text_you_can_send_to_friends_turns/http://www.securityfocus.com/bid/75491http://www.securitytracker.com/id/1032408http://zanzebek.com/a-simple-text-message-can-ruin-any-iphone/https://ghostbin.com/paste/zws9mhttps://support.apple.com/HT205221http://9to5mac.com/2015/05/27/how-to-fix-ios-text-message-bug-crash-reboot/http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.ibtimes.co.uk/apple-ios-bug-sees-message-app-crash-iphone-reboot-simply-by-receiving-message-1503083http://www.reddit.com/r/apple/comments/37e8c1/malicious_text_message/http://www.reddit.com/r/apple/comments/37enow/about_the_latest_iphone_security_vulnerability/http://www.reddit.com/r/explainlikeimfive/comments/37edde/eli5_how_that_text_you_can_send_to_friends_turns/http://www.securityfocus.com/bid/75491http://www.securitytracker.com/id/1032408http://zanzebek.com/a-simple-text-message-can-ruin-any-iphone/https://ghostbin.com/paste/zws9mhttps://support.apple.com/HT205221
2015-05-28
Published