PT-2016-6097 · Apple · Commoncrypto+3
Gergo Koteles
·
Publicado
2016-09-25
·
Atualizado
2017-07-30
·
CVE-2016-4711
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 10
Apple OS X versions prior to 10.12
Description
The issue allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output in CCrypt in corecrypto in CommonCrypto.
Recommendations
For Apple iOS versions prior to 10, update to iOS 10 or later.
For Apple OS X versions prior to 10.12, update to OS X 10.12 or later.
Correção
RCE
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Commoncrypto
Os X
Corecrypto
Ios