PT-2016-6097 · Apple · Commoncrypto+3
Gergo Koteles
·
Published
2016-09-25
·
Updated
2017-07-30
·
CVE-2016-4711
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 10
Apple OS X versions prior to 10.12
Description
The issue allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output in CCrypt in corecrypto in CommonCrypto.
Recommendations
For Apple iOS versions prior to 10, update to iOS 10 or later.
For Apple OS X versions prior to 10.12, update to OS X 10.12 or later.
Fix
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Commoncrypto
Os X
Corecrypto
Ios