CERT-In Advisory
CIAD-2017-0044
Multiple vulnerabilities in Apple iOS
Original Issue Date: September 26, 2017
Severity Rating: High
Software Affected
- Apple iOS versions prior to 11.0
Overview
Multiple vulnerabilities have been reported in Apple iOS which could allow a attacker to execute arbitrary code, spoof browser address bar, conduct cross site scripting, cause a denial of service (DoS) conditions or gain sensitive information and elevated privileges on the affected system.
Description
These vulnerabilities are caused due to multiple memory corruption issues, improper input validation, improper memory handling, and improper permission validation in various components within Webkit and various other components.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, spoof browser address bar, bypass security restrictions, conduct cross site scripting, cause a denial of service (DoS) conditions or gain sensitive information and gain elevated privileges on the affected system.
Solution
Apply appropriate security updates as mentioned in the
Apple Security Advisory HT208112
Vendor Information
Apple
https://support.apple.com/en-us/HT208112
References
Apple
https://support.apple.com/en-us/HT208112
Security Tracker
http://www.securitytracker.com/id/1039385
CVE Name
CVE-2017-7072
CVE-2017-7085
CVE-2017-7088
CVE-2017-7089
CVE-2017-7097
CVE-2017-7106
CVE-2017-7118
CVE-2017-7133
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|