Description
The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-1260 | The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app. |
References
History
No history.
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-06T04:33:20.571Z
Reserved: 2015-01-16T00:00:00.000Z
Link: CVE-2015-1117
No data.
Status : Modified
Published: 2015-04-10T14:59:31.747
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-1117
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD