PT-2023-6792 · Apple+6 · Apple Macos+6

Gertjan Franken

·

Publicado

2023-03-27

·

Atualizado

2025-01-28

·

CVE-2023-32370

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 13.3 WebKitGTK (affected versions not specified) WPE WebKit (affected versions not specified)
Description The issue is related to insufficient input validation, which may allow a remote attacker to impact data integrity. A logic issue was addressed with improved validation. The Content Security Policy to block domains with wildcards may fail.
Recommendations For macOS versions prior to 13.3, update to macOS Ventura 13.3 to resolve the issue. For WebKitGTK, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For WPE WebKit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:6535
ALSA-2023:7055
BDU:2023-07654
CESA-2023_7055
CVE-2023-32370
DSA-5396-1
DSA-5396-2
OPENSUSE-SU-2023_3753-1
RHSA-2023:6535
RHSA-2023:7055
RHSA-2023_6535
RHSA-2023_7055
RHSA-2025:10364
ROSA-SA-2025-2653
ROSA-SA-2025-2654
ROSA-SA-2025-2655
SUSE-SU-2023:3753-1

Produtos afetados

Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Suse