Buffer overflow in Apple iOS - CVE-2017-2518

 

Buffer overflow in Apple iOS - CVE-2017-2518

Published: May 16, 2017


Vulnerability identifier: #VU6582
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2518
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to buffer overflow when processing SQL queries. A remote attacker can send specially crafted SQL queries, trigger memory corruption and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may allow an attacker to gain complete control over affected system.


Affected software

Apple iOS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
EMC Integrated Data Protection Appliance
sqlite3 (Ubuntu package)
libsqlite3-0-debuginfo
sqlite3-devel
sqlite3-debugsource
sqlite3-debuginfo
sqlite3
libsqlite3-0-debuginfo-32bit
libsqlite3-0-32bit
libsqlite3-0
Dell EMC Data Protection Search
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2017-2518

Update to version 10.3.2.

EMC Integrated Data Protection Appliance - update to 2.7.1
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
Dell EMC Data Protection Search - update to 19.6.0
libsqlite3-0-debuginfo - update to 3.36.0-9.18.1
sqlite3-devel - update to 3.36.0-9.18.1
sqlite3-debugsource - update to 3.36.0-9.18.1
sqlite3-debuginfo - update to 3.36.0-9.18.1
sqlite3 - update to 3.36.0-9.18.1
libsqlite3-0-debuginfo-32bit - update to 3.36.0-9.18.1
libsqlite3-0-32bit - update to 3.36.0-9.18.1
libsqlite3-0 - update to 3.36.0-9.18.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins