Apple iOS HTTPProtocol remote code execution vulnerability in CVE-2015-8659)
Apple iOS HTTPProtocol remote code execution vulnerability in CVE-2015-8659)
Release date:
Updated on:
Affected Systems:
Apple iOS <9.3
Description:
CVE (CAN) ID: CVE-2015-8659
IOS is an operating system developed by Apple for mobile devices. It supports iPhone, iPod touch, iPad, and Apple TV.
In the implementation of HTTPProtocol in versions earlier than iOS 9.3, nghttp2 versions earlier than 1.6.0 have a security vulnerability, which can cause remote execution of arbitrary code.
<* Source: Apple
Link: https://support.apple.com/en-au/HT206166
*>
Suggestion:
Vendor patch:
Apple
-----
Apple has released a Security Bulletin (HT206166) for this purpose and the corresponding patch:
HT206166: About the security content of iOS 9.3
Link: https://support.apple.com/en-au/HT206166
This article permanently updates the link address: