CVE-2017-13802: Buffer Overflow
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-13802?
CVE-2017-13802 is a vulnerability that affects certain Apple products, including iOS, Safari, iCloud, iTunes, and tvOS.
Which versions of iOS are affected?
iOS versions before 11.1 are affected by CVE-2017-13802.
Which versions of Safari are affected?
Safari versions before 11.0.1 are affected by CVE-2017-13802.
Which versions of iCloud are affected?
iCloud versions before 7.1 on Windows are affected by CVE-2017-13802.
Which versions of iTunes are affected?
iTunes versions before 12.7.1 on Windows are affected by CVE-2017-13802.
Which versions of tvOS are affected?
tvOS versions before 11.1 are affected by CVE-2017-13802.
What is the severity of CVE-2017-13802?
The severity of CVE-2017-13802 is high, with a severity score of 8.8.
What is the Common Weakness Enumeration (CWE) of CVE-2017-13802?
The Common Weakness Enumeration (CWE) of CVE-2017-13802 is CWE-119.
Where can I find more information about CVE-2017-13802?
You can find more information about CVE-2017-13802 at the following references: [SecurityTracker](http://www.securitytracker.com/id/1039703), [Gentoo GLSA](https://security.gentoo.org/glsa/201712-01), [Apple support](https://support.apple.com/HT208219).