CVE-2015-5920

Publication date

2015-09-18 10:00:00

Family

apple

State

PUBLISHED

Description

The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.