PT-2017-2792 · Apple · Ios

Ben Seri

+1

·

Publicado

2017-09-12

·

Atualizado

2019-05-14

·

CVE-2017-14315

CVSS v2.0

7.9

Alta

VetorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple iOS versions 7 through 9
Description The issue is related to a flaw in the implementation of the Low Energy Audio Protocol (LEAP) in Apple iOS, which can lead to a heap overflow with attacker-controlled data when a large audio command is sent to a targeted device. This overflow can be exploited by an attacker to gain full control of the device, leveraging the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control but requires the default "Bluetooth On" value to be present in Settings.
Recommendations For Apple iOS versions 7 through 9, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02055
CVE-2017-14315

Produtos afetados

Ios