First published: Tue Sep 12 2017(Updated: )
CFNetwork. A memory corruption issue was addressed with improved memory handling.
Credit: Niklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend MicroNiklas Baumstark Samuel Gro Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <11 | 11 |
Apple tvOS | <11 | 11 |
Apple watchOS | <4 | 4 |
Apple iTunes for Windows | <12.7 | 12.7 |
Apple iCloud for Windows | <7.0 | 7.0 |
Apple macOS High Sierra | <10.13 | 10.13 |
Apple macOS High Sierra | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
Apple Mac OS X | <=10.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2017-13833 is a memory corruption vulnerability in the CFNetwork component of certain Apple products.
CVE-2017-13833 allows attackers to execute arbitrary code in a privileged context or cause a denial of service through memory corruption on macOS before version 10.13.1.
macOS High Sierra (versions up to and exclusive of 10.13.1), iTunes for Windows (version 12.7), watchOS (versions up to and exclusive of 4), iCloud for Windows (version 7.0), iOS (versions up to and exclusive of 11), and tvOS (versions up to and exclusive of 11) are affected by CVE-2017-13833.
CVE-2017-13833 has a severity score of 7.8 (out of 10.0), indicating a critical vulnerability.
To mitigate CVE-2017-13833, update your affected Apple products to the latest versions available from Apple's website.