First published: Tue Sep 19 2017(Updated: )
ImageIO. A memory corruption issue was addressed with improved input validation.
Credit: Australian Cyber Security Centre – Australian Signals Directorate Australian Cyber Security Centre – Australian Signals Directorate Australian Cyber Security Centre – Australian Signals Directorate Australian Cyber Security Centre – Australian Signals Directorate Australian Cyber Security Centre – Australian Signals Directorate product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <4 | 4 |
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
Apple macOS | <10.13 | 10.13 |
Apple macOS | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
macOS Yosemite | <=10.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID of this issue is CVE-2017-13814.
CVE-2017-13814 has a severity level of 7.8 (High).
macOS High Sierra (versions up to and including 10.13.1), Sierra, El Capitan, iOS (versions up to and excluding 11), tvOS (versions up to and excluding 11), Mac OS X (up to and including 10.13.0), watchOS (versions up to and excluding 4).
The vulnerability allows remote attackers to execute arbitrary code or cause a denial of service through memory corruption and application crash by exploiting a crafted image file.
Apply the appropriate security update provided by Apple for your affected product.