PT-2019-7828 · Apple · Tvos+2

Jerry Decime

·

Published

2019-01-11

·

Updated

2019-01-17

·

CVE-2016-4644

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 9.3.3 tvOS versions prior to 9.2.2 OS X El Capitan versions prior to 10.11.6 and Security Update 2016-004
Description A downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
Recommendations For iOS versions prior to 9.3.3, update to version 9.3.3 or later. For tvOS versions prior to 9.2.2, update to version 9.2.2 or later. For OS X El Capitan versions prior to 10.11.6 and Security Update 2016-004, update to version 10.11.6 and apply Security Update 2016-004.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4644

Affected Products

Os X El Capitan
Ios
Tvos