First published: Tue Sep 19 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.
Credit: found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.13.0 | |
Apple watchOS | <4 | 4 |
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
Apple macOS | <10.13 | 10.13 |
Apple macOS | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13813 is a vulnerability in the "libarchive" component affecting certain Apple products, allowing remote attackers to execute arbitrary code or cause a denial of service.
macOS before 10.13.1, watchOS 4, tvOS 11, and iOS 11 are among the affected Apple products.
The severity of CVE-2017-13813 is high with a CVSS score of 7.8.
Update your macOS, watchOS, tvOS, or iOS to the latest version provided by Apple as mentioned in their support articles.
You can find more information about CVE-2017-13813 on Apple's official support articles: [link1](https://support.apple.com/en-us/HT208115), [link2](https://support.apple.com/en-us/HT208221), [link3](https://support.apple.com/en-us/HT208113).