CVE-2015-1157
Last modified
CVE-2015-1157 is a vulnerability of currently unknown severity. CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.. EPSS estimates a 5.50% chance of exploitation in the next 30 days.
Description
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | 8.0 |
| Apple | Iphone Os | 8.0.1 |
| Apple | Iphone Os | 8.0.2 |
| Apple | Iphone Os | 8.1 |
| Apple | Iphone Os | 8.1.2 |
| Apple | Iphone Os | 8.1.3 |
| Apple | Iphone Os | 8.2 |
| Apple | Iphone Os | 8.3 |
| Apple | Mac Os X | <= 10.0.3 |
| Apple | Itunes | <= 12.2 |
References
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT204941Vendor Advisory
- http://support.apple.com/kb/HT204942Vendor Advisory
- https://support.apple.com/HT205221Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00003.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT204941Vendor Advisory
- http://support.apple.com/kb/HT204942Vendor Advisory
- https://support.apple.com/HT205221Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1157?
How severe is CVE-2015-1157?
How do I fix CVE-2015-1157?
Are you affected by CVE-2015-1157?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
