Vulnerability CVE-2015-5928: Information

Description

WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.

Severity: MEDIUM (6.8)

Published: Oct. 24, 2015
Modified: Dec. 24, 2016
Error type identifier: CWE-119

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libwebkitgtk2p102.4.11-alt12.4.11-alt13ALT-PU-2016-1315-1162826Fixed
libwebkitgtk2p92.4.11-alt12.4.11-alt10ALT-PU-2016-1315-1162826Fixed
libwebkitgtk2c10f12.4.11-alt12.4.11-alt13ALT-PU-2016-1315-1162826Fixed
libwebkitgtk2c9f22.4.11-alt12.4.11-alt10ALT-PU-2016-1315-1162826Fixed
libwebkitgtk3p102.4.10-alt12.4.11-alt12ALT-PU-2016-1245-1161352Fixed
libwebkitgtk3p92.4.10-alt12.4.11-alt9.1.p9ALT-PU-2016-1245-1161352Fixed
libwebkitgtk3c10f12.4.10-alt12.4.11-alt12ALT-PU-2016-1245-1161352Fixed
libwebkitgtk3c9f22.4.10-alt12.4.11-alt9.1.p9ALT-PU-2016-1245-1161352Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
      End including
      9.0

      cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
      End including
      9.0.2

      cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*
      End including
      12.3.0