ID

VAR-201504-0122


CVE

CVE-2015-1106


TITLE

Apple iOS Keyboard subsystem QuickType Vulnerabilities that passcodes can be obtained for functions

Trust: 0.8

sources: JVNDB: JVNDB-2015-002147

DESCRIPTION

The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard. Apple iOS is prone to multiple security vulnerabilities. Attackers can exploit these issues to gain sensitive information, perform unauthorized actions, bypass security restrictions, and perform other attacks. These issues affect iOS versions prior to 8.3. Apple iOS is an operating system developed by Apple (Apple) for mobile devices

Trust: 2.07

sources: NVD: CVE-2015-1106 // JVNDB: JVNDB-2015-002147 // BID: 73978 // VULHUB: VHN-79066 // VULMON: CVE-2015-1106

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:8.2

Trust: 1.0

vendor:applemodel:iosscope:ltversion:8.3 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:8.2

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

sources: BID: 73978 // JVNDB: JVNDB-2015-002147 // CNNVD: CNNVD-201504-131 // NVD: CVE-2015-1106

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1106
value: LOW

Trust: 1.0

NVD: CVE-2015-1106
value: LOW

Trust: 0.8

CNNVD: CNNVD-201504-131
value: LOW

Trust: 0.6

VULHUB: VHN-79066
value: LOW

Trust: 0.1

VULMON: CVE-2015-1106
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2015-1106
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-79066
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-79066 // VULMON: CVE-2015-1106 // JVNDB: JVNDB-2015-002147 // CNNVD: CNNVD-201504-131 // NVD: CVE-2015-1106

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-79066 // JVNDB: JVNDB-2015-002147 // NVD: CVE-2015-1106

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201504-131

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201504-131

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002147

PATCH

title:APPLE-SA-2015-04-08-3 iOS 8.3url:http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html

Trust: 0.8

title:HT204661url:http://support.apple.com/en-us/HT204661

Trust: 0.8

title:HT204661url:http://support.apple.com/ja-jp/HT204661

Trust: 0.8

title:OSXUpd10.10.3url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54848

Trust: 0.6

title:iPhone7,1_8.3_12F70_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54847

Trust: 0.6

title:AppleTV3,2_7.2_12F69_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54849

Trust: 0.6

sources: JVNDB: JVNDB-2015-002147 // CNNVD: CNNVD-201504-131

EXTERNAL IDS

db:NVDid:CVE-2015-1106

Trust: 2.9

db:BIDid:73978

Trust: 1.5

db:SECTRACKid:1032050

Trust: 1.2

db:JVNid:JVNVU91828320

Trust: 0.8

db:JVNDBid:JVNDB-2015-002147

Trust: 0.8

db:CNNVDid:CNNVD-201504-131

Trust: 0.7

db:VULHUBid:VHN-79066

Trust: 0.1

db:VULMONid:CVE-2015-1106

Trust: 0.1

sources: VULHUB: VHN-79066 // VULMON: CVE-2015-1106 // BID: 73978 // JVNDB: JVNDB-2015-002147 // CNNVD: CNNVD-201504-131 // NVD: CVE-2015-1106

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/apr/msg00002.html

Trust: 1.8

url:https://support.apple.com/ht204661

Trust: 1.8

url:http://www.securityfocus.com/bid/73978

Trust: 1.3

url:http://www.securitytracker.com/id/1032050

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1106

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91828320/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1106

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:https://support.apple.com/en-us/ht204661

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-79066 // VULMON: CVE-2015-1106 // BID: 73978 // JVNDB: JVNDB-2015-002147 // CNNVD: CNNVD-201504-131 // NVD: CVE-2015-1106

CREDITS

TaiG Jailbreak Team, Jarrod Dwenger, Steve Favorito, Paul Reedy of ConocoPhillips, Pedro Tavares of Molecular Biophysics at UCIBIO/FCT/UNL, De Paul Sunny, Christian Still of Evolve Media, Canada, Brent Erickson, Stuart Ryan of University of Technology, Syd

Trust: 0.3

sources: BID: 73978

SOURCES

db:VULHUBid:VHN-79066
db:VULMONid:CVE-2015-1106
db:BIDid:73978
db:JVNDBid:JVNDB-2015-002147
db:CNNVDid:CNNVD-201504-131
db:NVDid:CVE-2015-1106

LAST UPDATE DATE

2024-11-23T21:23:48.845000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-79066date:2017-01-03T00:00:00
db:VULMONid:CVE-2015-1106date:2017-01-03T00:00:00
db:BIDid:73978date:2015-05-07T17:36:00
db:JVNDBid:JVNDB-2015-002147date:2015-04-13T00:00:00
db:CNNVDid:CNNVD-201504-131date:2015-04-13T00:00:00
db:NVDid:CVE-2015-1106date:2024-11-21T02:24:41.107

SOURCES RELEASE DATE

db:VULHUBid:VHN-79066date:2015-04-10T00:00:00
db:VULMONid:CVE-2015-1106date:2015-04-10T00:00:00
db:BIDid:73978date:2015-04-08T00:00:00
db:JVNDBid:JVNDB-2015-002147date:2015-04-13T00:00:00
db:CNNVDid:CNNVD-201504-131date:2015-04-13T00:00:00
db:NVDid:CVE-2015-1106date:2015-04-10T14:59:21.857