ID

VAR-201510-0231


CVE

CVE-2015-5919


TITLE

Apple watchOS of GasGauge Vulnerability gained in

Trust: 0.8

sources: JVNDB: JVNDB-2015-005168

DESCRIPTION

GasGauge in Apple watchOS before 2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5918. Apple watchOS is prone to multiple local memory-corruption vulnerabilities. Attackers may be able to exploit these issues to execute arbitrary code with kernel-level privileges. Failed attack attempts will likely result in denial-of-service conditions. Apple watchOS is a smart watch operating system developed by Apple (Apple). GasGauge is one of the battery fuel gauge components. A security vulnerability exists in the GasGauge component of Apple watchOS 1.01 and earlier

Trust: 1.98

sources: NVD: CVE-2015-5919 // JVNDB: JVNDB-2015-005168 // BID: 76805 // VULHUB: VHN-83880

AFFECTED PRODUCTS

vendor:applemodel:watch osscope:lteversion:1.01

Trust: 1.0

vendor:applemodel:watchosscope:ltversion:2 (apple watch edition)

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:2 (apple watch sport)

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:2 (apple watch)

Trust: 0.8

vendor:applemodel:watch osscope:eqversion:1.01

Trust: 0.6

vendor:applemodel:watchosscope:eqversion:1.0.1

Trust: 0.3

vendor:applemodel:watchosscope:eqversion:1.0

Trust: 0.3

vendor:applemodel:watch sportscope:eqversion:0

Trust: 0.3

vendor:applemodel:watch editionscope:eqversion:0

Trust: 0.3

vendor:applemodel:watchscope:eqversion:0

Trust: 0.3

vendor:applemodel:watchosscope:neversion:2.0

Trust: 0.3

sources: BID: 76805 // JVNDB: JVNDB-2015-005168 // CNNVD: CNNVD-201510-119 // NVD: CVE-2015-5919

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-5919
value: HIGH

Trust: 1.0

NVD: CVE-2015-5919
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201510-119
value: HIGH

Trust: 0.6

VULHUB: VHN-83880
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-5919
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-83880
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-83880 // JVNDB: JVNDB-2015-005168 // CNNVD: CNNVD-201510-119 // NVD: CVE-2015-5919

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-83880 // JVNDB: JVNDB-2015-005168 // NVD: CVE-2015-5919

THREAT TYPE

local

Trust: 0.9

sources: BID: 76805 // CNNVD: CNNVD-201510-119

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201510-119

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005168

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:APPLE-SA-2015-09-21-1 watchOS 2url:http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html

Trust: 0.8

title:HT205213url:https://support.apple.com/en-us/HT205213

Trust: 0.8

title:HT205213url:http://support.apple.com/ja-jp/HT205213

Trust: 0.8

sources: JVNDB: JVNDB-2015-005168

EXTERNAL IDS

db:NVDid:CVE-2015-5919

Trust: 2.8

db:SECTRACKid:1033620

Trust: 1.1

db:JVNDBid:JVNDB-2015-005168

Trust: 0.8

db:CNNVDid:CNNVD-201510-119

Trust: 0.7

db:BIDid:76805

Trust: 0.3

db:VULHUBid:VHN-83880

Trust: 0.1

sources: VULHUB: VHN-83880 // BID: 76805 // JVNDB: JVNDB-2015-005168 // CNNVD: CNNVD-201510-119 // NVD: CVE-2015-5919

REFERENCES

url:http://lists.apple.com/archives/security-announce/2015/sep/msg00005.html

Trust: 1.7

url:https://support.apple.com/ht205213

Trust: 1.7

url:http://www.securitytracker.com/id/1033620

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-5919

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-5919

Trust: 0.8

url:http://www.apple.com/in/watch/

Trust: 0.3

url:http://www.apple.com/shop/buy-watch/apple-watch-sport/42mm-space-gray-aluminum-case-black-sport-band?product=mj3t2ll/a&step=detail

Trust: 0.3

url:http://www.apple.com/watchos-2/

Trust: 0.3

url:https://support.apple.com/en-us/ht205213

Trust: 0.3

sources: VULHUB: VHN-83880 // BID: 76805 // JVNDB: JVNDB-2015-005168 // CNNVD: CNNVD-201510-119 // NVD: CVE-2015-5919

CREDITS

Apple

Trust: 0.3

sources: BID: 76805

SOURCES

db:VULHUBid:VHN-83880
db:BIDid:76805
db:JVNDBid:JVNDB-2015-005168
db:CNNVDid:CNNVD-201510-119
db:NVDid:CVE-2015-5919

LAST UPDATE DATE

2024-11-23T22:31:06.474000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-83880date:2016-12-08T00:00:00
db:BIDid:76805date:2015-09-21T00:00:00
db:JVNDBid:JVNDB-2015-005168date:2015-10-13T00:00:00
db:CNNVDid:CNNVD-201510-119date:2015-10-10T00:00:00
db:NVDid:CVE-2015-5919date:2024-11-21T02:34:08.057

SOURCES RELEASE DATE

db:VULHUBid:VHN-83880date:2015-10-09T00:00:00
db:BIDid:76805date:2015-09-21T00:00:00
db:JVNDBid:JVNDB-2015-005168date:2015-10-13T00:00:00
db:CNNVDid:CNNVD-201510-119date:2015-10-10T00:00:00
db:NVDid:CVE-2015-5919date:2015-10-09T05:59:37.657