PT-2016-6097 · Apple · Commoncrypto+3

Gergo Koteles

·

Publicado

2016-09-25

·

Atualizado

2017-07-30

·

CVE-2016-4711

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iOS versions prior to 10 Apple OS X versions prior to 10.12
Description The issue allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output in CCrypt in corecrypto in CommonCrypto.
Recommendations For Apple iOS versions prior to 10, update to iOS 10 or later. For Apple OS X versions prior to 10.12, update to OS X 10.12 or later.

Correção

RCE

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4711

Produtos afetados

Commoncrypto
Os X
Corecrypto
Ios