PT-2016-6097 · Apple · Commoncrypto+3

Gergo Koteles

·

Published

2016-09-25

·

Updated

2017-07-30

·

CVE-2016-4711

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple iOS versions prior to 10 Apple OS X versions prior to 10.12
Description The issue allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output in CCrypt in corecrypto in CommonCrypto.
Recommendations For Apple iOS versions prior to 10, update to iOS 10 or later. For Apple OS X versions prior to 10.12, update to OS X 10.12 or later.

Fix

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4711

Affected Products

Commoncrypto
Os X
Corecrypto
Ios