ID

VAR-201504-0129


CVE

CVE-2015-1113


TITLE

Apple iOS Sandbox profile component of the latest contact phone number read vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-002181

DESCRIPTION

The Sandbox Profiles component in Apple iOS before 8.3 allows attackers to read the (1) telephone number or (2) e-mail address of a recent contact via a crafted app. (1) Phone number, or (2) Your email address may be read. Apple iOS is prone to multiple security vulnerabilities. Attackers can exploit these issues to gain sensitive information, perform unauthorized actions, bypass security restrictions, and perform other attacks. These issues affect iOS versions prior to 8.3. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. Sandbox Profiles is one of the Sandbox (Sandbox) components

Trust: 1.98

sources: NVD: CVE-2015-1113 // JVNDB: JVNDB-2015-002181 // BID: 73978 // VULHUB: VHN-79073

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:lteversion:8.2

Trust: 1.0

vendor:applemodel:iosscope:ltversion:8.3 (ipad 2 or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (iphone 4s or later )

Trust: 0.8

vendor:applemodel:iosscope:ltversion:8.3 (ipod touch first 5 after generation )

Trust: 0.8

vendor:applemodel:iphone osscope:eqversion:8.2

Trust: 0.6

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.9

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.8

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.7

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.10

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

sources: BID: 73978 // JVNDB: JVNDB-2015-002181 // CNNVD: CNNVD-201504-138 // NVD: CVE-2015-1113

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1113
value: LOW

Trust: 1.0

NVD: CVE-2015-1113
value: LOW

Trust: 0.8

CNNVD: CNNVD-201504-138
value: LOW

Trust: 0.6

VULHUB: VHN-79073
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2015-1113
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-79073
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-79073 // JVNDB: JVNDB-2015-002181 // CNNVD: CNNVD-201504-138 // NVD: CVE-2015-1113

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-79073 // JVNDB: JVNDB-2015-002181 // NVD: CVE-2015-1113

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201504-138

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201504-138

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002181

PATCH

title:APPLE-SA-2015-04-08-3 iOS 8.3url:http://lists.apple.com/archives/security-announce/2015/Apr/msg00002.html

Trust: 0.8

title:HT204661url:http://support.apple.com/en-us/HT204661

Trust: 0.8

title:HT204661url:http://support.apple.com/ja-jp/HT204661

Trust: 0.8

title:OSXUpd10.10.3url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54848

Trust: 0.6

title:iPhone7,1_8.3_12F70_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54847

Trust: 0.6

title:AppleTV3,2_7.2_12F69_Restoreurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54849

Trust: 0.6

sources: JVNDB: JVNDB-2015-002181 // CNNVD: CNNVD-201504-138

EXTERNAL IDS

db:NVDid:CVE-2015-1113

Trust: 2.8

db:BIDid:73978

Trust: 1.4

db:SECTRACKid:1032050

Trust: 1.1

db:JVNid:JVNVU91828320

Trust: 0.8

db:JVNDBid:JVNDB-2015-002181

Trust: 0.8

db:CNNVDid:CNNVD-201504-138

Trust: 0.7

db:VULHUBid:VHN-79073

Trust: 0.1

sources: VULHUB: VHN-79073 // BID: 73978 // JVNDB: JVNDB-2015-002181 // CNNVD: CNNVD-201504-138 // NVD: CVE-2015-1113

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/apr/msg00002.html

Trust: 1.7

url:https://support.apple.com/ht204661

Trust: 1.7

url:http://www.securityfocus.com/bid/73978

Trust: 1.1

url:http://www.securitytracker.com/id/1032050

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1113

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91828320/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1113

Trust: 0.8

url:http://www.apple.com/ios/

Trust: 0.3

url:http://www.apple.com/ipad/

Trust: 0.3

url:http://www.apple.com/iphone/

Trust: 0.3

url:http://www.apple.com/ipodtouch/

Trust: 0.3

url:https://support.apple.com/en-us/ht204661

Trust: 0.3

sources: VULHUB: VHN-79073 // BID: 73978 // JVNDB: JVNDB-2015-002181 // CNNVD: CNNVD-201504-138 // NVD: CVE-2015-1113

CREDITS

TaiG Jailbreak Team, Jarrod Dwenger, Steve Favorito, Paul Reedy of ConocoPhillips, Pedro Tavares of Molecular Biophysics at UCIBIO/FCT/UNL, De Paul Sunny, Christian Still of Evolve Media, Canada, Brent Erickson, Stuart Ryan of University of Technology, Syd

Trust: 0.3

sources: BID: 73978

SOURCES

db:VULHUBid:VHN-79073
db:BIDid:73978
db:JVNDBid:JVNDB-2015-002181
db:CNNVDid:CNNVD-201504-138
db:NVDid:CVE-2015-1113

LAST UPDATE DATE

2024-11-23T20:38:07.914000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-79073date:2017-01-03T00:00:00
db:BIDid:73978date:2015-05-07T17:36:00
db:JVNDBid:JVNDB-2015-002181date:2015-04-14T00:00:00
db:CNNVDid:CNNVD-201504-138date:2015-04-14T00:00:00
db:NVDid:CVE-2015-1113date:2024-11-21T02:24:41.973

SOURCES RELEASE DATE

db:VULHUBid:VHN-79073date:2015-04-10T00:00:00
db:BIDid:73978date:2015-04-08T00:00:00
db:JVNDBid:JVNDB-2015-002181date:2015-04-14T00:00:00
db:CNNVDid:CNNVD-201504-138date:2015-04-14T00:00:00
db:NVDid:CVE-2015-1113date:2015-04-10T14:59:28.263