PT-2016-2715 · Apple · Os X

Fuzzerdotcn

+1

·

Publicado

2016-07-22

·

Atualizado

2017-09-01

·

CVE-2016-4649

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apple OS X versions prior to 10.11.6
Description The issue is related to a denial of service caused by a NULL pointer dereference in the Audio component of Apple OS X. Additionally, there are reports of vulnerabilities in the login window and other components, including buffer overflows, insufficient input validation, and errors in memory initialization, which could allow an attacker to elevate privileges, execute arbitrary code, or cause a denial of service. The vulnerabilities can be exploited locally or remotely using specially crafted applications or files.
Recommendations For Apple OS X versions prior to 10.11.6, update to version 10.11.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Audio component and other vulnerable features to minimize the risk of exploitation. Avoid using the vulnerable components until the issue is resolved.

Correção

Buffer Overflow

RCE

Information Disclosure

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2016-02109
BDU:2016-02110
BDU:2016-02111
BDU:2016-02112
BDU:2016-02113
BDU:2016-02114
BDU:2016-02115
BDU:2016-02116
BDU:2016-02117
CVE-2016-4649

Produtos afetados

Os X