ID

VAR-201510-0233


CVE

CVE-2015-5923


TITLE

Apple iOS Vulnerable to reading user contact data

Trust: 0.8

sources: JVNDB: JVNDB-2015-005169

DESCRIPTION

Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors. Apple iOS is prone to a local security-bypass vulnerability. Attackers with physical access to the device can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. The vulnerability is caused by the program not properly restricting the options in the lock screen state. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2015-09-30-01 iOS 9.0.2 iOS 9.0.2 is now available and addresses the following: Lock Screen Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: A person with physical access to an iOS device may be able to access photos and contacts from the lock screen Description: A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting options offered on a locked device. CVE-ID CVE-2015-5923 Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "9.0.2". Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Comment: GPGTools - http://gpgtools.org iQIcBAEBCAAGBQJWCywnAAoJEBcWfLTuOo7tsbkP/A6aLss8SQXXBjrlKdLbAcWF x/zkFEwnHVG77cfXPwyEHnlqssVV/oc3Ynds6VdUmB4LiIT56NJc7Yl2eteg+PN7 rVePaHZ2iHBqkdT6uoeFqTDirTcc/a01crBtIp9VS8vmbKovzdNwuaVHswX1dsWd FnHA04tf/g028f+mZ5r+fvgvP35jVJZZem0aLln2EIaxB4qIwTLzLZlXt6Wwg54q tf8xcGERemCzeiVHf3XUhZlZBwdGIya+MNNS7DZxQ9+9aqlinMmnlC8Ub66UAI9C 24FphpZfMibBFh/PEBYarFnEA4DxNbFSL6wivVD4vjlgiFLLlcXpPtBU0DseOVDu spkUzYb0enjj0SZhxguxaIrUTqrtGLR0fqkQSOv1RITMalBeRvE6HDbO8U12Q5aM C1VTu0nR/6rzFOjhI1RhMLCsceuSEGCEv10ODZGzYkV2FEYiBeFU3ROloW4NqYf4 MRKwMj2SVeySjzh6qh5i5fgFsd3YUug4AnLr0Uy5Rz9xsF3CaUkvdPfksVgh/IyF fGKr/pKqqWTguTNWYoDSaf/l0jTKceke8HVd04o8nIUjw6yOTk1MsKZ2WWFuQiaE V/ZCF+ssugHCm8k7zKnjYHhe4kp5v2Q4mJ/VzOGVcqOMABi33lm6yAnRFOPSld98 ACylj1OKP3rLyDKeEwRh =7WtW -----END PGP SIGNATURE-----

Trust: 2.07

sources: NVD: CVE-2015-5923 // JVNDB: JVNDB-2015-005169 // BID: 76821 // VULHUB: VHN-83884 // PACKETSTORM: 133801

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:9.0.1

Trust: 1.0

vendor:applemodel:iosscope:ltversion:9.0.2 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:9.0.2 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:9.0.2 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:9.0.1

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

sources: BID: 76821 // JVNDB: JVNDB-2015-005169 // CNNVD: CNNVD-201510-121 // NVD: CVE-2015-5923

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-5923
value: LOW

Trust: 1.0

NVD: CVE-2015-5923
value: LOW

Trust: 0.8

CNNVD: CNNVD-201510-121
value: LOW

Trust: 0.6

VULHUB: VHN-83884
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2015-5923
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-83884
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-83884 // JVNDB: JVNDB-2015-005169 // CNNVD: CNNVD-201510-121 // NVD: CVE-2015-5923

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-83884 // JVNDB: JVNDB-2015-005169 // NVD: CVE-2015-5923

THREAT TYPE

local

Trust: 0.9

sources: BID: 76821 // CNNVD: CNNVD-201510-121

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201510-121

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005169

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-83884

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:APPLE-SA-2015-09-30-01 iOS 9.0.2url:http://lists.apple.com/archives/security-announce/2015/Sep/msg00006.html

Trust: 0.8

title:HT205284url:https://support.apple.com/en-us/HT205284

Trust: 0.8

title:HT205284url:http://support.apple.com/ja-jp/HT205284

Trust: 0.8

sources: JVNDB: JVNDB-2015-005169

EXTERNAL IDS

db:NVDid:CVE-2015-5923

Trust: 2.9

db:SECTRACKid:1033687

Trust: 1.1

db:JVNid:JVNVU97220341

Trust: 0.8

db:JVNDBid:JVNDB-2015-005169

Trust: 0.8

db:CNNVDid:CNNVD-201510-121

Trust: 0.7

db:BIDid:76821

Trust: 0.4

db:PACKETSTORMid:133801

Trust: 0.2

db:VULHUBid:VHN-83884

Trust: 0.1

sources: VULHUB: VHN-83884 // BID: 76821 // JVNDB: JVNDB-2015-005169 // PACKETSTORM: 133801 // CNNVD: CNNVD-201510-121 // NVD: CVE-2015-5923

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/sep/msg00006.html

Trust: 1.7

url:https://support.apple.com/ht205284

Trust: 1.7

url:http://www.securitytracker.com/id/1033687

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-5923

Trust: 0.8

url:http://jvn.jp/vu/jvnvu97220341/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-5923

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://support.apple.com/kb/ht201222

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-5923

Trust: 0.1

url:http://gpgtools.org

Trust: 0.1

sources: VULHUB: VHN-83884 // BID: 76821 // JVNDB: JVNDB-2015-005169 // PACKETSTORM: 133801 // CNNVD: CNNVD-201510-121 // NVD: CVE-2015-5923

CREDITS

Anonymous

Trust: 0.3

sources: BID: 76821

SOURCES

db:VULHUBid:VHN-83884
db:BIDid:76821
db:JVNDBid:JVNDB-2015-005169
db:PACKETSTORMid:133801
db:CNNVDid:CNNVD-201510-121
db:NVDid:CVE-2015-5923

LAST UPDATE DATE

2025-04-13T20:07:06.516000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-83884date:2016-12-08T00:00:00
db:BIDid:76821date:2015-10-26T16:51:00
db:JVNDBid:JVNDB-2015-005169date:2015-10-13T00:00:00
db:CNNVDid:CNNVD-201510-121date:2015-10-10T00:00:00
db:NVDid:CVE-2015-5923date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-83884date:2015-10-09T00:00:00
db:BIDid:76821date:2015-09-22T00:00:00
db:JVNDBid:JVNDB-2015-005169date:2015-10-13T00:00:00
db:PACKETSTORMid:133801date:2015-10-01T16:14:58
db:CNNVDid:CNNVD-201510-121date:2015-10-10T00:00:00
db:NVDid:CVE-2015-5923date:2015-10-09T05:59:39.657