CVE-2017-2368: Input Validation
Contacts. An input validation issue existed in the parsing of contact cards. This issue was addressed through improved input validation.
Other sources
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What devices are affected by CVE-2017-2368?
CVE-2017-2368 affects Apple devices running iOS versions prior to 10.2.1.
What is the severity of CVE-2017-2368?
CVE-2017-2368 is classified as a high severity vulnerability due to potential remote exploitation.
How do I fix CVE-2017-2368?
To fix CVE-2017-2368, upgrade your device to iOS version 10.2.1 or later.
What type of issue is described in CVE-2017-2368?
CVE-2017-2368 describes an input validation issue in the parsing of contact cards.
Can CVE-2017-2368 lead to remote attacks?
Yes, CVE-2017-2368 allows remote attackers to exploit the vulnerability through crafted contact cards.