PT-2017-3076 · Apple · Watchos+2

Gal Beniamini

·

Published

2017-06-21

·

Updated

2019-03-08

·

CVE-2017-7103

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iOS versions prior to 11 tvOS versions prior to 11 watchOS versions prior to 4
Description The issue involves the Wi-Fi component and might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic. The vulnerability is caused by a buffer overflow in the memory, which can be exploited by a remote attacker using specially crafted Wi-Fi traffic.
Recommendations For iOS versions prior to 11, update to version 11 or later to resolve the issue. For tvOS versions prior to 11, update to version 11 or later to resolve the issue. For watchOS versions prior to 4, update to version 4 or later to resolve the issue. As a temporary workaround, consider disabling the Wi-Fi component until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02446
CVE-2017-7103

Affected Products

Ios
Tvos
Watchos