First published: Mon Sep 25 2017(Updated: )
An issue in handling file permissions was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, macOS High Sierra 10.13. A local attacker may be able to execute non-executable text files via an SMB share.
Credit: an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS High Sierra | <10.13.1 | 10.13.1 |
Apple Sierra | ||
Apple El Capitan | ||
Apple Mac OS X | >=10.11<10.11.6 | |
Apple Mac OS X | >=10.12<=10.12.5 | |
Apple Mac OS X | =10.11.6 | |
Apple Mac OS X | =10.11.6-security_update_2016-001 | |
Apple Mac OS X | =10.11.6-security_update_2016-002 | |
Apple Mac OS X | =10.11.6-security_update_2016-003 | |
Apple Mac OS X | =10.11.6-security_update_2017-001 | |
Apple Mac OS X | =10.11.6-security_update_2017-002 | |
Apple Mac OS X | =10.11.6-security_update_2017-003 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2017-13908.
The severity of CVE-2017-13908 is high with a CVSS score of 7.8.
CVE-2017-13908 affects macOS High Sierra versions 10.13 and 10.13.1.
CVE-2017-13908 is fixed in Security Update 2017-001 Sierra and Security Update 2017-004 El Capitan.
A local attacker may be able to execute non-executable text files.