CERT-In Advisory
CIAD-2017-0056
Multiple Vulnerabilities in Apple macOS
Original Issue Date: December 13, 2017
Severity Rating: High
Software Affected
- Apple macOS Sierra 10.12.6, 10.13, 10.13.1, and OS X El Capitan 10.11.6
Overview
Multiple vulnerabilities have been reported in Apple macOS/OS X that could allow a remote attacker to execute arbitrary code, cause an application to terminate unexpectedly ,cause denial of service (DoS) conditions or gain potentially sensitive information and elevated privileges on the target system.
Description
These vulnerabilities are due to improper memory handling, insufficient validation of user-supplied input and insufficient bounds checking by the affected software.
An attacker could exploit these vulnerabilities by persuading a targeted user to open a crafted file or execute a malicious application.
Solution
Apply appropriate security updates as mentioned in the
Apple Security Advisory HT208331
Vendor Information
Apple
https://support.apple.com/en-us/HT208331
References
Apple
https://support.apple.com/en-us/HT208331
Security Tracker
https://securitytracker.com/id/1039966
CVE Name
CVE-2017-13826
CVE-2017-13833
CVE-2017-13847
CVE-2017-13848
CVE-2017-13855
CVE-2017-13858
CVE-2017-13860
CVE-2017-13862
CVE-2017-13865
CVE-2017-13867
CVE-2017-13868
CVE-2017-13869
CVE-2017-13871
CVE-2017-13875
CVE-2017-13876
CVE-2017-13878
CVE-2017-13883
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|