#VU31446 Buffer overflow in tvOS - CVE-2016-7626
Published: February 20, 2017 / Updated: July 20, 2020
tvOS
Apple Inc.
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS before 3.1.1 is affected. The issue involves the "Profiles" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted certificate profile.
Remediation
External links
- http://www.securityfocus.com/bid/94852
- http://www.securitytracker.com/id/1037429
- https://lists.apple.com/archives/security-announce/2016/Dec/msg00001.html
- https://support.apple.com/HT207422
- https://support.apple.com/HT207425
- https://support.apple.com/HT207487
- https://www.exploit-db.com/exploits/40906/