First published: Tue Sep 19 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted archive file.
Credit: found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.13.0 | |
Apple macOS High Sierra | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
Apple iOS | <11 | 11 |
Apple tvOS | <11 | 11 |
Apple watchOS | <4 | 4 |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13812 is a vulnerability in the libarchive component of certain Apple products that allows remote attackers to execute arbitrary code or cause a denial of service.
macOS versions before 10.13.1, macOS High Sierra versions up to 10.13, Apple Sierra, Apple El Capitan, Apple tvOS up to version 11, Apple iOS up to version 11, and Apple watchOS up to version 4 are affected by CVE-2017-13812.
CVE-2017-13812 has a severity rating of 7.8 out of 10, which is considered high.
To fix CVE-2017-13812, update your macOS or other affected Apple products to the latest version available.
You can find more information about CVE-2017-13812 on Apple's official support page at the following links: [link1], [link2], [link3].