Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Pekka Oikarainen

Pesquisador deSynopsys Software Integrity Group
#14541de 53,638
18.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2017-1773
9.3
2017-04-02
Apple · Apple Macos · CVE-2017-2420
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.4 **Description** The issue is related to a buffer overflow in the Bluetooth component of the operating system, which can be exploited by a remote attacker to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) using a specially crafted application. **Recommendations** For macOS versions prior to 10.12.4, update to version 10.12.4 or later to resolve the issue.
PT-2017-1352
9.3
2017-02-20
Apple · Apple Macos · CVE-2016-7596
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.2 **Description** The issue involves the `Bluetooth` component and allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. This is caused by a buffer overflow in the Bluetooth component, which can be exploited by a remote attacker to achieve the aforementioned effects. **Recommendations** For macOS versions prior to 10.12.2, update to version 10.12.2 or later to resolve the issue. As a temporary workaround, consider disabling the Bluetooth component until a patch is available. Restrict access to the Bluetooth functionality to minimize the risk of exploitation.