CERT-In Advisory
CIAD-2017-0057
Multiple Vulnerabilities in Apple iOS
Original Issue Date: December 14, 2017
Severity Rating: High
Software Affected
- Apple iOS versions prior to 11.2
Overview
Multiple vulnerabilities have been reported in Apple iOS which could allow an attacker to execute arbitrary code ,obtain potentially sensitive information and gain elevated privileges on the affected system.
Description
These vulnerabilities are caused due to multiple memory corruption issues, improper input validation, improper memory handling, improper permission validation in various components within IOKit , kernel, IOSurface , IOMobileFrameBuffer and various other components.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, obtain sensitive information and gain elevated privileges on the affected system.
Solution
Apply appropriate security updates as mentioned in the
Apple Security Advisory HT208334
Vendor Information
Apple
https://support.apple.com/en-us/HT208334
References
Apple
https://support.apple.com/en-us/HT208334
Security Tracker
https://securitytracker.com/id/1039953
CVE Name
CVE-2017-13833
CVE-2017-13847
CVE-2017-13855
CVE-2017-13860
CVE-2017-13861
CVE-2017-13862
CVE-2017-13865
CVE-2017-13867
CVE-2017-13868
CVE-2017-13869
CVE-2017-13874
CVE-2017-13876
CVE-2017-13879
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|