First published: Sun Sep 25 2016(Updated: )
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <=9.3.5 | |
macOS Yosemite | <=10.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4711 is rated as a high-severity vulnerability due to its potential to expose cleartext information.
To remediate CVE-2016-4711, upgrade your Apple iOS to version 10 or later, or macOS to version 10.12 or later.
CVE-2016-4711 affects Apple iOS versions prior to 10.0.
CVE-2016-4711 impacts macOS versions prior to 10.12.
CVE-2016-4711 allows attackers to exploit a function call vulnerability that can lead to information disclosure.