Memory corruption in Apple Inc. products - CVE-2017-7160
Published: March 22, 2018 / Updated: March 22, 2018
Vulnerability identifier: #VU11213
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7160
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error. A remote attacker can trigger memory corruption and execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
iCloud for Windows
Apple iOS
Gentoo Linux
Ubuntu
Fedora
Opensuse
Apple Safari
iTunes
webkitgtk4
Apple iOS
Gentoo Linux
Ubuntu
Fedora
Opensuse
Apple Safari
iTunes
webkitgtk4
How to mitigate CVE-2017-7160
Update to versions iOS 11.2, Safari 11.0.2, iCloud 7.2 on Windows, iTunes 12.7.2 on Windows or tvOS 11.2.
webkitgtk4 - addressed in versions 2.18.6-1.fc26, 2.18.6-1.fc27