First published: Tue Sep 19 2017(Updated: )
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.
Credit: Gal Beniamini Google Project ZeroGal Beniamini Google Project Zero cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
Broadcom Bcm4355c0 Firmware | <=9.44.78.27.0.1.56 | |
Broadcom BCM4355C0 | ||
Apple iPhone OS | <=10.3.3 | |
Apple tvOS | <=10.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2017-11122.
The severity of CVE-2017-11122 is high with a severity value of 7.5.
CVE-2017-11122 is a validation issue that was addressed with improved input sanitization in Wi-Fi. It can lead to an information leak due to insufficient length validation in Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, specifically related to ICMPv6 router advertisement offloading.
For Apple devices, iOS versions up to 10.3.3 and tvOS versions up to 10.2.2 are affected by CVE-2017-11122. Apple has provided a remedy with the release of iOS 11 and tvOS 11.
You can find more information about CVE-2017-11122 at the following references: - [Packet Storm Security](http://packetstormsecurity.com/files/144461/Broadcom-ICMPv6-Information-Leak.html) - [Chromium Project Zero](https://bugs.chromium.org/p/project-zero/issues/detail?id=1300) - [Apple Support](https://support.apple.com/HT208112)