Description
iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205635
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205637
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1034344
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Dec/msg00005.html
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Dec/msg00000.html
Scores
EPSS
0.0211
EPSS Percentile
79.9%
Details
Status
published
Products (2)
apple/iphone_os
< 9.1
apple/mac_os_x
< 10.11.1
Published
Dec 11, 2015
Tracked Since
Feb 18, 2026