The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.kb.cert.org/vuls/id/877625 | third party advisory us government resource |
https://support.apple.com/HT206567 | vendor advisory |
http://lists.apple.com/archives/security-announce/2016/May/msg00004.html | mailing list vendor advisory |
https://support.apple.com/HT206564 | vendor advisory |
http://www.securitytracker.com/id/1035890 | vdb entry third party advisory |
http://lists.apple.com/archives/security-announce/2016/May/msg00002.html | mailing list vendor advisory |
http://www.securityfocus.com/bid/90697 | vdb entry third party advisory |
https://support.apple.com/HT206568 | vendor advisory |
http://lists.apple.com/archives/security-announce/2016/May/msg00001.html | mailing list vendor advisory |