ID

VAR-201503-0075


CVE

CVE-2015-1062


TITLE

Apple iOS and Apple TV of MobileStorageMounter Vulnerable to creating folders in arbitrary file system locations

Trust: 0.8

sources: JVNDB: JVNDB-2015-001784

DESCRIPTION

MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app. Supplementary information : CWE Vulnerability type by CWE-19: Data Handling ( Data processing ) Has been identified. Apple TV and iOS are prone to a local security-bypass vulnerability. Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2015-03-09-1 iOS 8.2 iOS 8.2 is now available and addresses the following: CoreTelephony Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A remote attacker can cause a device to unexpectedly restart Description: A null pointer dereference issue existed in CoreTelephony's handling of Class 0 SMS messages. This issue was addressed through improved message validation. CVE-ID CVE-2015-1063 : Roman Digerberg, Sweden iCloud Keychain Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: An attacker with a privileged network position may be able to execute arbitrary code Description: Multiple buffer overflows existed in the handling of data during iCloud Keychain recovery. These issues were addressed through improved bounds checking. CVE-ID CVE-2015-1065 : Andrey Belenko of NowSecure IOSurface Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A malicious application may be able to execute arbitrary code with system privileges Description: A type confusion issue existed in IOSurface's handling of serialized objects. The issue was addressed through additional type checking. CVE-ID CVE-2015-1061 : Ian Beer of Google Project Zero MobileStorageMounter Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A malicious application may be able to create folders in trusted locations in the file system Description: An issue existed in the developer disk mounting logic which resulted in invalid disk image folders not being deleted. This was addressed through improved error handling. CVE-ID CVE-2015-1062 : TaiG Jailbreak Team Secure Transport Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: An attacker with a privileged network position may intercept SSL/TLS connections Description: Secure Transport accepted short ephemeral RSA keys, usually used only in export-strength RSA cipher suites, on connections using full-strength RSA cipher suites. This issue, also known as FREAK, only affected connections to servers which support export-strength RSA cipher suites, and was addressed by removing support for ephemeral RSA keys. CVE-ID CVE-2015-1067 : Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Alfredo Pironti, and Jean Karim Zinzindohoue of Prosecco at Inria Paris Springboard Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A person with physical access to the device may be able to see the home screen of the device even if the device is not activated Description: An unexpected application termination during activation could have caused the device to show the home screen. The issue was addressed through improved error handling during activation. CVE-ID CVE-2015-1064 Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "8.2". Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.22 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJU/fWsAAoJEBcWfLTuOo7t7VUQAIsLCBlvhkiqbJ4xdanG1RZI Ld7787ljx6ksnLMiFJNCECOIm3fk7TKMUfFn7HXYR/hg/w0GPb7dXUNkNh9IhdjF H8dur2Eb3iR3EPDhnGvPcgic059SKKgVUgyzMfr8td3onswWq90aG+8eAgq3ri9B qAL8wUSoXDz0VPUJ2H7VcktfcdXqFmS5lPGa8PpEAzNAhN+utsw61yoJgILHh9g6 5axRobZFpd7CKy+ADPUtlMUYQQliRX+BNX+ZZgh1bsEmXJMmeHxKjEN6Iq18ObD7 ucFihWs6WFroDHuHMvuR/yJARqInChMzd/EMkjSfHH2ldSbTyGmsTp/4D1aofQMp V6D8JjsHvdb/jWq5qCmFEBXf1VpXXqvNI1rq3D7qHOIJJPQH5afzI9ujymOrsspH Li0lD2TrwnLJznoRgAGVYSo0dhouUmhRYkd4zJkQMoR/Rn/aL3xWGT5XhFEkfdFD rvFv0LgaiC/5jbLZczUVk1yYQTkJ4mM8h02GnHd1CLvSdf1naEvTw3goBJguI233 5R89HVZA0Z2P6Vyk1bn5V0SWYasVATmjfr89lkhESVVfszakEvxTxmg4fZ65Gwtq MWSMUBzFZT09abSUEH27BYVGYoe1HCk8sAKlOhMvd1s2O54kZbHeuIMvfrYT5C0d 3T50q8/I5HSn+5c9eHvz =l+X4 -----END PGP SIGNATURE-----

Trust: 2.16

sources: NVD: CVE-2015-1062 // JVNDB: JVNDB-2015-001784 // BID: 73003 // VULHUB: VHN-79022 // PACKETSTORM: 130742 // PACKETSTORM: 130741

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:8.1.3

Trust: 1.0

vendor:applemodel:tvosscope:lteversion:7.0.3

Trust: 1.0

vendor:applemodel:tvscope:eqversion:7.0.3

Trust: 0.9

vendor:applemodel:tvscope:ltversion:7.1 (apple tv first 3 after generation )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.2 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.2 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.2 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:8.1.3

Trust: 0.6

vendor:applemodel:iosscope:eqversion:8

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.2.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7

Trust: 0.3

vendor:applemodel:tvscope:eqversion:3.0.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:6.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.2.1

Trust: 0.3

vendor:applemodel:tvscope:neversion:7.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.1.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:2.3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.4.3

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.3

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.4

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.4.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.0.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:2.2.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.1.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.6

Trust: 0.3

vendor:applemodel:tvscope:eqversion:6.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:6.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.1.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.4

Trust: 0.3

vendor:applemodel:tvscope:eqversion:6.0.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:7.0.1

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:7

Trust: 0.3

vendor:applemodel:tvscope:eqversion:6.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6

Trust: 0.3

vendor:applemodel:tvscope:eqversion:2.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:8.1.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.3.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:3.0.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:2.4.0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:1.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:tvscope:eqversion:6.1.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.1.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:tvscope:eqversion:7.0.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:3.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.1.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:tvscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:6.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:neversion:8.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:tvscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:7.0.1

Trust: 0.3

sources: BID: 73003 // JVNDB: JVNDB-2015-001784 // CNNVD: CNNVD-201503-289 // NVD: CVE-2015-1062

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1062
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-1062
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201503-289
value: MEDIUM

Trust: 0.6

VULHUB: VHN-79022
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-1062
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-79022
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-79022 // JVNDB: JVNDB-2015-001784 // CNNVD: CNNVD-201503-289 // NVD: CVE-2015-1062

PROBLEMTYPE DATA

problemtype:CWE-19

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-79022 // JVNDB: JVNDB-2015-001784 // NVD: CVE-2015-1062

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201503-289

TYPE

Design Error

Trust: 0.3

sources: BID: 73003

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001784

PATCH

title:APPLE-SA-2015-03-09-1 iOS 8.2url:http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.html

Trust: 0.8

title:APPLE-SA-2015-03-09-2 AppleTV 7.1url:http://lists.apple.com/archives/security-announce/2015/Mar/msg00001.html

Trust: 0.8

title:HT204423url:http://support.apple.com/en-us/HT204423

Trust: 0.8

title:HT204426url:http://support.apple.com/en-us/HT204426

Trust: 0.8

title:HT204423url:http://support.apple.com/ja-jp/HT204423

Trust: 0.8

title:HT204426url:http://support.apple.com/ja-jp/HT204426

Trust: 0.8

title:iPhone7,1_8.2_12D508_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54079

Trust: 0.6

sources: JVNDB: JVNDB-2015-001784 // CNNVD: CNNVD-201503-289

EXTERNAL IDS

db:NVDid:CVE-2015-1062

Trust: 3.0

db:SECTRACKid:1031864

Trust: 1.7

db:JVNid:JVNVU90171154

Trust: 0.8

db:JVNDBid:JVNDB-2015-001784

Trust: 0.8

db:CNNVDid:CNNVD-201503-289

Trust: 0.7

db:BIDid:73003

Trust: 0.4

db:VULHUBid:VHN-79022

Trust: 0.1

db:PACKETSTORMid:130742

Trust: 0.1

db:PACKETSTORMid:130741

Trust: 0.1

sources: VULHUB: VHN-79022 // BID: 73003 // JVNDB: JVNDB-2015-001784 // PACKETSTORM: 130742 // PACKETSTORM: 130741 // CNNVD: CNNVD-201503-289 // NVD: CVE-2015-1062

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/mar/msg00000.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2015/mar/msg00001.html

Trust: 1.7

url:https://support.apple.com/ht204423

Trust: 1.7

url:https://support.apple.com/ht204426

Trust: 1.7

url:http://www.securitytracker.com/id/1031864

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1062

Trust: 0.8

url:http://jvn.jp/vu/jvnvu90171154/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1062

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:https://www.apple.com/in/appletv/

Trust: 0.3

url:https://support.apple.com/en-us/ht204426

Trust: 0.3

url:https://support.apple.com/en-us/ht204423

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-1062

Trust: 0.2

url:https://www.apple.com/support/security/pgp/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-1067

Trust: 0.2

url:https://support.apple.com/kb/ht1222

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-1061

Trust: 0.2

url:http://gpgtools.org

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-1065

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1064

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1063

Trust: 0.1

sources: VULHUB: VHN-79022 // BID: 73003 // JVNDB: JVNDB-2015-001784 // PACKETSTORM: 130742 // PACKETSTORM: 130741 // CNNVD: CNNVD-201503-289 // NVD: CVE-2015-1062

CREDITS

TaiG Jailbreak Team.

Trust: 0.3

sources: BID: 73003

SOURCES

db:VULHUBid:VHN-79022
db:BIDid:73003
db:JVNDBid:JVNDB-2015-001784
db:PACKETSTORMid:130742
db:PACKETSTORMid:130741
db:CNNVDid:CNNVD-201503-289
db:NVDid:CVE-2015-1062

LAST UPDATE DATE

2025-04-13T22:58:39.439000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-79022date:2019-03-08T00:00:00
db:BIDid:73003date:2015-03-10T00:00:00
db:JVNDBid:JVNDB-2015-001784date:2015-03-13T00:00:00
db:CNNVDid:CNNVD-201503-289date:2019-03-13T00:00:00
db:NVDid:CVE-2015-1062date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-79022date:2015-03-12T00:00:00
db:BIDid:73003date:2015-03-10T00:00:00
db:JVNDBid:JVNDB-2015-001784date:2015-03-13T00:00:00
db:PACKETSTORMid:130742date:2015-03-10T16:17:57
db:PACKETSTORMid:130741date:2015-03-10T16:14:34
db:CNNVDid:CNNVD-201503-289date:2015-03-13T00:00:00
db:NVDid:CVE-2015-1062date:2015-03-12T10:59:06.880