CVE-2015-5746
published 2015-08-17CVE-2015-5746: AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.42%
70.2th percentile
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 8.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-5746: iOS 8.4.1
vendor_apple·CVSS 5.0
CVE-2015-5746 [MEDIUM] CVE-2015-5746: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-5746
Component: CVE-ID
GHSA
GHSA-j9qf-q9qf-j8gv: AppleFileConduit in Apple iOS before 8
ghsa_unreviewed·2022-05-17
CVE-2015-5746 [MEDIUM] CWE-284 GHSA-j9qf-q9qf-j8gv: AppleFileConduit in Apple iOS before 8
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://www.securityfocus.com/bid/76337http://www.securitytracker.com/id/1033275https://support.apple.com/kb/HT205030http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.htmlhttp://www.securityfocus.com/bid/76337http://www.securitytracker.com/id/1033275https://support.apple.com/kb/HT205030
2015-08-17
Published