CVE-2017-2355: Buffer Overflow
WebKit. A memory initialization issue was addressed through improved memory handling.
Other sources
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access and application crash) via a crafted web site.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-2355?
CVE-2017-2355 has a high severity rating due to its memory initialization issue that could potentially allow for remote code execution.
How do I fix CVE-2017-2355?
To fix CVE-2017-2355, update to iOS 10.2.1, Safari 10.0.3, iCloud 6.1.1, iTunes 12.5.5, or tvOS 10.1.1 as appropriate.
Which systems are affected by CVE-2017-2355?
CVE-2017-2355 affects iOS versions prior to 10.2.1, Safari versions prior to 10.0.3, iCloud versions prior to 6.1.1, iTunes versions prior to 12.5.5, and tvOS versions prior to 10.1.1.
What products does CVE-2017-2355 impact?
CVE-2017-2355 impacts Apple products including iOS devices, Safari browser, iCloud for Windows, iTunes for Windows, and tvOS.
Is CVE-2017-2355 related to a specific software component?
Yes, CVE-2017-2355 is related to the WebKit component, specifically its memory handling capabilities.