ID

VAR-201503-0078


CVE

CVE-2015-1065


TITLE

Apple iOS and Apple OS X of iCloud Keychain buffer overflow vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-001781

DESCRIPTION

Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery. Apple Mac OS X and iOS are prone to multiple buffer-overflow vulnerabilities because they fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. An attacker can leverage these issues to execute arbitrary code with system privileges. Failed exploit attempts will likely result in denial-of-service conditions. Both Apple iOS and OS X are operating systems of Apple Inc. in the United States. Apple iOS was developed for mobile devices; OS X was developed for Mac computers. CVE-ID CVE-2015-1061 : Ian Beer of Google Project Zero Note: Security Update 2015-003 includes the content of Security Update 2015-002. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2015-03-09-1 iOS 8.2 iOS 8.2 is now available and addresses the following: CoreTelephony Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A remote attacker can cause a device to unexpectedly restart Description: A null pointer dereference issue existed in CoreTelephony's handling of Class 0 SMS messages. This issue was addressed through improved message validation. These issues were addressed through improved bounds checking. CVE-ID CVE-2015-1065 : Andrey Belenko of NowSecure IOSurface Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A malicious application may be able to execute arbitrary code with system privileges Description: A type confusion issue existed in IOSurface's handling of serialized objects. The issue was addressed through additional type checking. CVE-ID CVE-2015-1061 : Ian Beer of Google Project Zero MobileStorageMounter Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A malicious application may be able to create folders in trusted locations in the file system Description: An issue existed in the developer disk mounting logic which resulted in invalid disk image folders not being deleted. This was addressed through improved error handling. CVE-ID CVE-2015-1062 : TaiG Jailbreak Team Secure Transport Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: An attacker with a privileged network position may intercept SSL/TLS connections Description: Secure Transport accepted short ephemeral RSA keys, usually used only in export-strength RSA cipher suites, on connections using full-strength RSA cipher suites. This issue, also known as FREAK, only affected connections to servers which support export-strength RSA cipher suites, and was addressed by removing support for ephemeral RSA keys. CVE-ID CVE-2015-1067 : Benjamin Beurdouche, Karthikeyan Bhargavan, Antoine Delignat-Lavaud, Alfredo Pironti, and Jean Karim Zinzindohoue of Prosecco at Inria Paris Springboard Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A person with physical access to the device may be able to see the home screen of the device even if the device is not activated Description: An unexpected application termination during activation could have caused the device to show the home screen. The issue was addressed through improved error handling during activation. CVE-ID CVE-2015-1064 Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "8.2". Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.22 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJU/fWsAAoJEBcWfLTuOo7t7VUQAIsLCBlvhkiqbJ4xdanG1RZI Ld7787ljx6ksnLMiFJNCECOIm3fk7TKMUfFn7HXYR/hg/w0GPb7dXUNkNh9IhdjF H8dur2Eb3iR3EPDhnGvPcgic059SKKgVUgyzMfr8td3onswWq90aG+8eAgq3ri9B qAL8wUSoXDz0VPUJ2H7VcktfcdXqFmS5lPGa8PpEAzNAhN+utsw61yoJgILHh9g6 5axRobZFpd7CKy+ADPUtlMUYQQliRX+BNX+ZZgh1bsEmXJMmeHxKjEN6Iq18ObD7 ucFihWs6WFroDHuHMvuR/yJARqInChMzd/EMkjSfHH2ldSbTyGmsTp/4D1aofQMp V6D8JjsHvdb/jWq5qCmFEBXf1VpXXqvNI1rq3D7qHOIJJPQH5afzI9ujymOrsspH Li0lD2TrwnLJznoRgAGVYSo0dhouUmhRYkd4zJkQMoR/Rn/aL3xWGT5XhFEkfdFD rvFv0LgaiC/5jbLZczUVk1yYQTkJ4mM8h02GnHd1CLvSdf1naEvTw3goBJguI233 5R89HVZA0Z2P6Vyk1bn5V0SWYasVATmjfr89lkhESVVfszakEvxTxmg4fZ65Gwtq MWSMUBzFZT09abSUEH27BYVGYoe1HCk8sAKlOhMvd1s2O54kZbHeuIMvfrYT5C0d 3T50q8/I5HSn+5c9eHvz =l+X4 -----END PGP SIGNATURE----- . CVE-ID CVE-2015-1061 : Ian Beer of Google Project Zero Kernel Available for: OS X Yosemite v10.10.2 Impact: Maliciously crafted or compromised applications may be able to determine addresses in the kernel Description: The mach_port_kobject kernel interface leaked kernel addresses and heap permutation value, which may aid in bypassing address space layout randomization protection. This was addressed by disabling the mach_port_kobject interface in production configurations

Trust: 2.25

sources: NVD: CVE-2015-1065 // JVNDB: JVNDB-2015-001781 // BID: 73007 // VULHUB: VHN-79025 // PACKETSTORM: 130938 // PACKETSTORM: 130741 // PACKETSTORM: 130743

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:8.1.3

Trust: 1.0

vendor:applemodel:mac os xscope:lteversion:10.10.2

Trust: 1.0

vendor:applemodel:mac os xscope:ltversion:10.10.2

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.2 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.2 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.2 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:8.1.3

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.10.2

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.1.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.7

Trust: 0.3

vendor:cosmicperlmodel:directory proscope:eqversion:10.0.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.4.11

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.1

Trust: 0.3

sources: BID: 73007 // JVNDB: JVNDB-2015-001781 // CNNVD: CNNVD-201503-292 // NVD: CVE-2015-1065

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1065
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-1065
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201503-292
value: MEDIUM

Trust: 0.6

VULHUB: VHN-79025
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-1065
severity: MEDIUM
baseScore: 5.4
vectorString: AV:A/AC:M/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-79025
severity: MEDIUM
baseScore: 5.4
vectorString: AV:A/AC:M/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-79025 // JVNDB: JVNDB-2015-001781 // CNNVD: CNNVD-201503-292 // NVD: CVE-2015-1065

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-79025 // JVNDB: JVNDB-2015-001781 // NVD: CVE-2015-1065

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201503-292

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201503-292

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001781

PATCH

title:APPLE-SA-2015-03-19-1 Security Update 2015-003url:http://lists.apple.com/archives/security-announce/2015/Mar/msg00005.html

Trust: 0.8

title:APPLE-SA-2015-03-09-1 iOS 8.2url:http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.html

Trust: 0.8

title:APPLE-SA-2015-03-09-3 Security Update 2015-002url:http://lists.apple.com/archives/security-announce/2015/Mar/msg00002.html

Trust: 0.8

title:HT204563url:https://support.apple.com/en-us/HT204563

Trust: 0.8

title:HT204423url:http://support.apple.com/en-us/HT204423

Trust: 0.8

title:HT204413url:http://support.apple.com/en-us/HT204413

Trust: 0.8

title:HT204563url:http://support.apple.com/ja-jp/HT204563

Trust: 0.8

title:HT204423url:http://support.apple.com/ja-jp/HT204423

Trust: 0.8

title:HT204413url:http://support.apple.com/ja-jp/HT204413

Trust: 0.8

title:iPhone7,1_8.2_12D508_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54079

Trust: 0.6

sources: JVNDB: JVNDB-2015-001781 // CNNVD: CNNVD-201503-292

EXTERNAL IDS

db:NVDid:CVE-2015-1065

Trust: 3.1

db:BIDid:73007

Trust: 1.4

db:SECTRACKid:1031864

Trust: 1.1

db:JVNid:JVNVU93102213

Trust: 0.8

db:JVNid:JVNVU90171154

Trust: 0.8

db:JVNDBid:JVNDB-2015-001781

Trust: 0.8

db:CNNVDid:CNNVD-201503-292

Trust: 0.7

db:VULHUBid:VHN-79025

Trust: 0.1

db:PACKETSTORMid:130938

Trust: 0.1

db:PACKETSTORMid:130741

Trust: 0.1

db:PACKETSTORMid:130743

Trust: 0.1

sources: VULHUB: VHN-79025 // BID: 73007 // JVNDB: JVNDB-2015-001781 // PACKETSTORM: 130938 // PACKETSTORM: 130741 // PACKETSTORM: 130743 // CNNVD: CNNVD-201503-292 // NVD: CVE-2015-1065

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/mar/msg00000.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2015/mar/msg00002.html

Trust: 1.7

url:https://support.apple.com/ht204413

Trust: 1.7

url:https://support.apple.com/ht204423

Trust: 1.7

url:http://www.securityfocus.com/bid/73007

Trust: 1.1

url:https://support.apple.com/kb/ht204563

Trust: 1.1

url:http://www.securitytracker.com/id/1031864

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1065

Trust: 0.8

url:http://jvn.jp/vu/jvnvu90171154/index.html

Trust: 0.8

url:http://jvn.jp/vu/jvnvu93102213/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1065

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:https://www.apple.com/osx/

Trust: 0.3

url:https://support.apple.com/en-us/ht204563

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-1065

Trust: 0.3

url:https://www.apple.com/support/security/pgp/

Trust: 0.3

url:https://support.apple.com/kb/ht1222

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2015-1061

Trust: 0.3

url:http://gpgtools.org

Trust: 0.3

url:http://www.apple.com/support/downloads/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-1067

Trust: 0.2

url:https://support.apple.com/en-us/ht204413

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1064

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1062

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1063

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1066

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-4496

Trust: 0.1

sources: VULHUB: VHN-79025 // BID: 73007 // JVNDB: JVNDB-2015-001781 // PACKETSTORM: 130938 // PACKETSTORM: 130741 // PACKETSTORM: 130743 // CNNVD: CNNVD-201503-292 // NVD: CVE-2015-1065

CREDITS

Andrey Belenko of NowSecure.

Trust: 0.3

sources: BID: 73007

SOURCES

db:VULHUBid:VHN-79025
db:BIDid:73007
db:JVNDBid:JVNDB-2015-001781
db:PACKETSTORMid:130938
db:PACKETSTORMid:130741
db:PACKETSTORMid:130743
db:CNNVDid:CNNVD-201503-292
db:NVDid:CVE-2015-1065

LAST UPDATE DATE

2025-04-13T22:00:05.550000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-79025date:2016-12-08T00:00:00
db:BIDid:73007date:2015-04-13T20:02:00
db:JVNDBid:JVNDB-2015-001781date:2015-03-23T00:00:00
db:CNNVDid:CNNVD-201503-292date:2015-03-13T00:00:00
db:NVDid:CVE-2015-1065date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-79025date:2015-03-12T00:00:00
db:BIDid:73007date:2015-03-09T00:00:00
db:JVNDBid:JVNDB-2015-001781date:2015-03-13T00:00:00
db:PACKETSTORMid:130938date:2015-03-21T17:32:22
db:PACKETSTORMid:130741date:2015-03-10T16:14:34
db:PACKETSTORMid:130743date:2015-03-10T16:20:32
db:CNNVDid:CNNVD-201503-292date:2015-03-13T00:00:00
db:NVDid:CVE-2015-1065date:2015-03-12T10:59:09.990