AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://support.apple.com/kb/HT205030 | vendor advisory |
http://www.securitytracker.com/id/1033275 | vdb entry |
http://www.securityfocus.com/bid/76337 | vdb entry |
http://lists.apple.com/archives/security-announce/2015/Aug/msg00002.html | vendor advisory |