CVE Vulnerabilities

CVE-2015-7023

Published: Oct 23, 2015 | Modified: Dec 24, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple * 10.11.0 (including)

References