PT-2021-7572 · Apple · Model I/O+5

Mickey Jin

+1

·

Published

2021-08-24

·

Updated

2022-02-22

·

CVE-2021-30979

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to 12.1 iOS versions prior to 15.2 iPadOS versions prior to 15.2 macOS Big Sur versions prior to 11.6.2 macOS Catalina versions prior to Security Update 2021-008
Description A buffer overflow issue was addressed with improved memory handling. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution. The vulnerability is related to the Model I/O component and is caused by a lack of input size validation, allowing an attacker to execute arbitrary code or cause a denial of service with a specially crafted malicious USD file.
Recommendations For macOS versions prior to 12.1, update to macOS Monterey 12.1 or later. For iOS versions prior to 15.2, update to iOS 15.2 or later. For iPadOS versions prior to 15.2, update to iPadOS 15.2 or later. For macOS Big Sur versions prior to 11.6.2, update to macOS Big Sur 11.6.2 or later. For macOS Catalina versions prior to Security Update 2021-008, apply Security Update 2021-008 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00095
CVE-2021-30979
ZDI-22-358

Affected Products

Apple Macos
Model I/O
Ios
Ipados
Macos Big Sur
Macos Catalina