DescriptionCFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.
PhaseAssigned (16.09.2015)
ReferencesAPPLE : APPLE-SA-2015-10-21-1
 APPLE : APPLE-SA-2015-10-21-4
SecurityVulns:Apple iOS multiple security vulnerabilities
 Apple Mac OS X / Mac EFI / OS X Server multiple security vulnerabilities
