Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1065
Reference (s):
- APPLE:APPLE-SA-2015-03-09-1
- URL: http://lists.apple.com/archives/security-announce/2015/Mar/msg00000.html
- APPLE:APPLE-SA-2015-03-09-3
- URL: http://lists.apple.com/archives/security-announce/2015/Mar/msg00002.html
- BID:73007