First published: Tue Sep 12 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service via a crafted image.
Credit: Glen Carmichael Glen Carmichael Glen Carmichael Glen Carmichael Glen Carmichael Glen Carmichael Glen Carmichael product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.13.0 | |
Apple iCloud for Windows | <7.0 | 7.0 |
Apple macOS High Sierra | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
Apple iTunes for Windows | <12.7 | 12.7 |
Apple iOS | <11 | 11 |
Apple tvOS | <11 | 11 |
Apple watchOS | <4 | 4 |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2017-13831 is a memory corruption issue in the ImageIO component of certain Apple products that allows remote attackers to obtain sensitive information or cause a denial of service via a crafted image.
macOS before 10.13.1, iCloud for Windows up to version 7.0, macOS High Sierra up to version 10.13.1, Sierra, El Capitan, tvOS up to version 11, iOS up to version 11, iTunes for Windows up to version 12.7, and watchOS up to version 4 are affected by CVE-2017-13831.
CVE-2017-13831 has a severity rating of 7.1 (high).
To fix CVE-2017-13831, update to macOS 10.13.1 or later, iCloud for Windows 7.0.1 or later, macOS High Sierra 10.13.2 or later, or update to the latest version of the affected software.
You can find more information about CVE-2017-13831 on the Apple support website at the following links: [Link 1](https://support.apple.com/en-us/HT208141), [Link 2](https://support.apple.com/en-us/HT208115), [Link 3](https://support.apple.com/en-us/HT208221).