CVE-2015-7023
published 2015-10-23CVE-2015-7023: CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which…
PriorityP428medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.63%
73.7th percentile
CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.0.2 | — |
| apple | mac_os_x | <= 10.11.0 | — |
| apple | os_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-66f8-xmpj-j79x: CFNetwork in Apple iOS before 9
ghsa_unreviewed·2022-05-17
CVE-2015-7023 [MEDIUM] GHSA-66f8-xmpj-j79x: CFNetwork in Apple iOS before 9
CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.
Apple
CVE-2015-7023: iOS 9.1
vendor_apple·CVSS 5.8
CVE-2015-7023 [MEDIUM] CVE-2015-7023: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7023
Component: CVE-ID
Impact: A malicious application may be able to elevate privileges
Description: A heap based buffer overflow issue existed in the DNS client library. A malicious application with the ability to spoof responses from the local configd service may have been able to cause arbitrary code execution in DNS clients.
Apple
CVE-2015-7023: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
vendor_apple·CVSS 5.8
CVE-2015-7023 [MEDIUM] CVE-2015-7023: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Product: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
CVE: CVE-2015-7023
Component: CVE-ID
Impact: A malicious application may be able to elevate privileges
Description: A heap based buffer overflow issue existed in the DNS client library. A malicious application with the ability to spoof responses from the local configd service may have been able to cause arbitrary code execution in DNS clients.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Oct/msg00005.htmlhttp://www.securityfocus.com/bid/77263http://www.securitytracker.com/id/1033929https://support.apple.com/HT205370https://support.apple.com/HT205375http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Oct/msg00005.htmlhttp://www.securityfocus.com/bid/77263http://www.securitytracker.com/id/1033929https://support.apple.com/HT205370https://support.apple.com/HT205375
2015-10-23
Published