Memory corruption in Apple Inc. products - CVE-2016-4738

 

Memory corruption in Apple Inc. products - CVE-2016-4738

Published: September 13, 2016 / Updated: April 4, 2018


Vulnerability identifier: #VU3592
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4738
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to boundary error. A remote attacker can trigger memory corruption and execute arbitrary code.

Successful exploitation of the vulnerability my result in system compromise.

Affected software

watchOS
tvOS
Apple iOS
macOS
Debian Linux
Gentoo Linux

How to mitigate CVE-2016-4738

Update to Apple iOS 10, OS X 10.12, tvOS 10 or watchOS 3.


External References

Related Security Bulletins