First published: Mon Sep 25 2017(Updated: )
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A malicious application may be able to elevate privileges.
Credit: CVE-2017-13906 CVE-2017-13906 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | >=10.11<10.11.6 | |
Apple Mac OS X | >=10.12<=10.12.5 | |
Apple Mac OS X | =10.11.6 | |
Apple Mac OS X | =10.11.6-security_update_2016-001 | |
Apple Mac OS X | =10.11.6-security_update_2016-002 | |
Apple Mac OS X | =10.11.6-security_update_2016-003 | |
Apple Mac OS X | =10.11.6-security_update_2017-001 | |
Apple Mac OS X | =10.11.6-security_update_2017-002 | |
Apple Mac OS X | =10.11.6-security_update_2017-003 | |
Apple macOS | <10.13 | 10.13 |
Apple macOS | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-13906 is a memory corruption vulnerability in the IOAcceleratorFamily component of Apple macOS High Sierra and earlier versions.
CVE-2017-13906 has a severity rating of 7.8 (high).
CVE-2017-13906 affects macOS High Sierra 10.13.1, 10.13, Sierra, and El Capitan.
A malicious application can exploit the memory corruption vulnerability in CVE-2017-13906 to elevate privileges.
CVE-2017-13906 is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan.