CVE-2016-7667: Input Validation
Published Feb 20, 2017
·Updated
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service via a crafted string.
Affected Software
2 affected components
Apple iPhone OS<=10.1.1
Apple iOS and macOS<=10.12.1
Event History
Feb 20, 2017
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
Description
Data Sourced
via NVD·08:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7667?
CVE-2016-7667 has a severity rating that indicates it can lead to denial of service on affected devices.
2
How do I fix CVE-2016-7667?
To fix CVE-2016-7667, update your iOS to version 10.2 or later and macOS to version 10.12.2 or later.
3
Which Apple products are affected by CVE-2016-7667?
CVE-2016-7667 affects iOS versions before 10.2 and macOS versions before 10.12.2.
4
What component is involved in CVE-2016-7667?
CVE-2016-7667 involves the CoreText component within the affected Apple products.
5
Can CVE-2016-7667 be exploited remotely?
Yes, CVE-2016-7667 can be exploited remotely through a crafted string.