CVE-2015-7988

6 documents4 sources
Severity
9.8CRITICAL
EPSS
2.6%
top 14.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 14

Description

The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

NVDapple/mdnsresponder< 625.41.2
NVDapple/watchos< 2.1
NVDapple/mac_os_x10.910.9.5+2
NVDapple/iphone_os9.09.1

🔴Vulnerability Details

2
GHSA
GHSA-wj37-2wrq-j2mg: The handle_regservice_request function in mDNSResponder before 6252022-05-14
CVEList
CVE-2015-7988: The handle_regservice_request function in mDNSResponder before 6252016-06-26

📋Vendor Advisories

3
Apple
CVE-2015-7988: iOS 9.1
Apple
CVE-2015-7988: OS X El Capitan 10.11.1, Security Update 2015-004 Yosemite, and Security Update 2015-007 Mavericks
Apple
CVE-2015-7988: watchOS 2.1
CVE-2015-7988 (CRITICAL CVSS 9.8) | The handle_regservice_request funct | cvebase.io