Memory corruption in Apple Inc. products - CVE-2017-7160

 

Memory corruption in Apple Inc. products - CVE-2017-7160

Published: March 22, 2018 / Updated: March 22, 2018


Vulnerability identifier: #VU11213
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7160
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error. A remote attacker can trigger memory corruption and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

iCloud for Windows
Apple iOS
Gentoo Linux
Ubuntu
Fedora
Opensuse
Apple Safari
iTunes
webkitgtk4

How to mitigate CVE-2017-7160

Update to versions iOS 11.2, Safari 11.0.2, iCloud 7.2 on Windows, iTunes 12.7.2 on Windows or tvOS 11.2.

webkitgtk4 - addressed in versions 2.18.6-1.fc26, 2.18.6-1.fc27

External References

Related Security Bulletins