CVE-2015-7006Path Traversal in Apple Iphone OS

CWE-22Path Traversal5 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
1.3%
top 20.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 17

Description

Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages6 packages

NVDapple/watchos2.0.0
Appleapple/watchos2.0.1
NVDapple/mac_os_x10.11.0
NVDapple/iphone_os9.0.2
Appleapple/ios9.1

🔴Vulnerability Details

1
GHSA
GHSA-pc4j-hm8h-32rp: Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 92022-05-17

📋Vendor Advisories

3
Apple
CVE-2015-7006: watchOS 2.0.1
Apple
CVE-2015-7006: iOS 9.1
Apple
CVE-2015-7006: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks