CVE-2015-7059
published 2015-12-11CVE-2015-7059: The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.24%
81.0th percentile
The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7060 and CVE-2015-7061.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | mac_os_x | <= 10.11.1 | — |
| apple | os_x_el_capitan_10.11.1_security_update_2015-004_yosemite_and_security_update_20 | — | — |
| apple | os_x_el_capitan_10.11.2_security_update_2015-005_yosemite_and_security_update_20 | — | — |
| apple | tvos | <= 9.0 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.0 | — |
| apple | watchos | — | — |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.29+esm10 | 5.5.9+dfsg-1ubuntu4.29+esm10 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87j2-fp97-jmf2: The ASN
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2015-7060 [MEDIUM] CWE-119 GHSA-87j2-fp97-jmf2: The ASN
The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7059 and CVE-2015-7061.
GHSA
GHSA-2whp-98g5-c7fv: The ASN
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2015-7061 [MEDIUM] CWE-119 GHSA-2whp-98g5-c7fv: The ASN
The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7059 and CVE-2015-7060.
GHSA
GHSA-r44g-r7jh-28pg: The ASN
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2015-7059 [MEDIUM] CWE-119 GHSA-r44g-r7jh-28pg: The ASN
The ASN.1 decoder in Apple OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate, a different vulnerability than CVE-2015-7060 and CVE-2015-7061.
OSV
php7.0 regression
osv·2020-02-19·CVSS 6.5
CVE-2015-9253 php7.0 regression
php7.0 regression
USN-4279-1 fixed vulnerabilities in PHP. The updated packages caused a regression.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that PHP incorrectly handled certain scripts.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and Ubuntu 16.04 LTS.
(CVE-2015-9253)
It was discovered that PHP incorrectly handled certain inputs. An attacker
could possibly use this issue to expose sensitive information.
(CVE-2020-7059)
It was discovered that PHP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
a
OSV
php5, php7.0, php7.2, php7.3 vulnerabilities
osv·2020-02-17·CVSS 6.5
CVE-2015-9253 php5, php7.0, php7.2, php7.3 vulnerabilities
php5, php7.0, php7.2, php7.3 vulnerabilities
It was discovered that PHP incorrectly handled certain scripts.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and Ubuntu 16.04 LTS.
(CVE-2015-9253)
It was discovered that PHP incorrectly handled certain inputs. An attacker
could possibly use this issue to expose sensitive information.
(CVE-2020-7059)
It was discovered that PHP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
and Ubuntu 19.10. (CVE-2020-7060)
Apple
CVE-2015-7059: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
vendor_apple·CVSS 6.8
CVE-2015-7059 [MEDIUM] CVE-2015-7059: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Product: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
CVE: CVE-2015-7059
Component: CVE-ID
Apple
CVE-2015-7059: tvOS 9.1
vendor_apple·CVSS 6.8
CVE-2015-7059 [MEDIUM] CVE-2015-7059: tvOS 9.1
Apple Security Update: About the security content of tvOS 9.1
Product: tvOS
Version: 9.1
CVE: CVE-2015-7059
Component: CVE-ID
Apple
CVE-2015-7059: watchOS 2.1
vendor_apple·CVSS 6.8
CVE-2015-7059 [MEDIUM] CVE-2015-7059: watchOS 2.1
Apple Security Update: About the security content of watchOS 2.1
Product: watchOS
Version: 2.1
CVE: CVE-2015-7059
Component: CVE-ID
Apple
CVE-2015-7059: iOS 9.1
vendor_apple·CVSS 6.8
CVE-2015-7059 [MEDIUM] CVE-2015-7059: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7059
Component: CVE-ID
Apple
CVE-2015-7059: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
vendor_apple·CVSS 6.8
CVE-2015-7059 [MEDIUM] CVE-2015-7059: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Product: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
CVE: CVE-2015-7059
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Dec/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://www.securitytracker.com/id/1034344https://support.apple.com/HT205637https://support.apple.com/HT205640https://support.apple.com/HT205641http://lists.apple.com/archives/security-announce/2015/Dec/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Dec/msg00005.htmlhttp://www.securitytracker.com/id/1034344https://support.apple.com/HT205637https://support.apple.com/HT205640https://support.apple.com/HT205641
2015-12-11
Published