Описание
CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.
Ссылки
- Mailing ListVendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListVendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 5.1 (исключая)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00556
Низкий
5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
около 3 лет назад
CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.
EPSS
Процентиль: 67%
0.00556
Низкий
5 Medium
CVSS2
Дефекты
CWE-20