First published: Fri Feb 21 2020(Updated: )
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Haxx Curl | <7.49.1 | |
Apple Mac OS X | <10.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-4606 is critical with a score of 9.8.
CVE-2016-4606 is a vulnerability in Apple OS X before macOS Sierra 10.12 that allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions.
CVE-2016-4606 affects Haxx Curl versions up to exclusive 7.49.1, allowing attackers to exploit the vulnerability.
To fix CVE-2016-4606, update to a version of Apple macOS Sierra 10.12.0 or above.
More information about CVE-2016-4606 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/93055), [SecurityTracker](http://www.securitytracker.com/id/1036858), [Apple Security Announce](https://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html).