Improper access control in Apple iOS - CVE-2017-13844
Published: November 1, 2017
Vulnerability identifier: #VU9022
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13844
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists due to a flaw in the Messages application. A local attacker can supply Reply With Message and access photos from the lock screen.
The weakness exists due to a flaw in the Messages application. A local attacker can supply Reply With Message and access photos from the lock screen.
Affected software
Apple iOS
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
libsoftokn3-debuginfo
mozilla-nss-sysinit-32bit-debuginfo
mozilla-nss-sysinit-32bit
mozilla-nss-certs-32bit-debuginfo
libsoftokn3-32bit-debuginfo
libfreebl3-32bit
mozilla-nss-32bit-debuginfo
libfreebl3-32bit-debuginfo
mozilla-nss-32bit
libsoftokn3-32bit
mozilla-nss-certs-32bit
mozilla-nss-debuginfo
libfreebl3
mozilla-nss
mozilla-nss-sysinit-debuginfo
mozilla-nss-sysinit
mozilla-nss-tools-debuginfo
libfreebl3-debuginfo
mozilla-nss-certs-debuginfo
mozilla-nss-tools
mozilla-nss-devel
mozilla-nss-debugsource
mozilla-nss-certs
libsoftokn3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
libsoftokn3-debuginfo
mozilla-nss-sysinit-32bit-debuginfo
mozilla-nss-sysinit-32bit
mozilla-nss-certs-32bit-debuginfo
libsoftokn3-32bit-debuginfo
libfreebl3-32bit
mozilla-nss-32bit-debuginfo
libfreebl3-32bit-debuginfo
mozilla-nss-32bit
libsoftokn3-32bit
mozilla-nss-certs-32bit
mozilla-nss-debuginfo
libfreebl3
mozilla-nss
mozilla-nss-sysinit-debuginfo
mozilla-nss-sysinit
mozilla-nss-tools-debuginfo
libfreebl3-debuginfo
mozilla-nss-certs-debuginfo
mozilla-nss-tools
mozilla-nss-devel
mozilla-nss-debugsource
mozilla-nss-certs
libsoftokn3
How to mitigate CVE-2017-13844
Update to version 11.1.
libsoftokn3-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit-32bit-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-certs-32bit-debuginfo - update to 3.101.1-150000.3.117.1
libsoftokn3-32bit-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-32bit-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3-32bit-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-32bit - update to 3.101.1-150000.3.117.1
libsoftokn3-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-certs-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3 - update to 3.101.1-150000.3.117.1
mozilla-nss - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit - update to 3.101.1-150000.3.117.1
mozilla-nss-tools-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-certs-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-tools - update to 3.101.1-150000.3.117.1
mozilla-nss-devel - update to 3.101.1-150000.3.117.1
mozilla-nss-debugsource - update to 3.101.1-150000.3.117.1
mozilla-nss-certs - update to 3.101.1-150000.3.117.1
libsoftokn3 - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit-32bit-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-certs-32bit-debuginfo - update to 3.101.1-150000.3.117.1
libsoftokn3-32bit-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-32bit-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3-32bit-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-32bit - update to 3.101.1-150000.3.117.1
libsoftokn3-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-certs-32bit - update to 3.101.1-150000.3.117.1
mozilla-nss-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3 - update to 3.101.1-150000.3.117.1
mozilla-nss - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-sysinit - update to 3.101.1-150000.3.117.1
mozilla-nss-tools-debuginfo - update to 3.101.1-150000.3.117.1
libfreebl3-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-certs-debuginfo - update to 3.101.1-150000.3.117.1
mozilla-nss-tools - update to 3.101.1-150000.3.117.1
mozilla-nss-devel - update to 3.101.1-150000.3.117.1
mozilla-nss-debugsource - update to 3.101.1-150000.3.117.1
mozilla-nss-certs - update to 3.101.1-150000.3.117.1
libsoftokn3 - update to 3.101.1-150000.3.117.1