CVE-2017-2370: Buffer Overflow
Kernel. A buffer overflow issue was addressed through improved memory handling.
Other sources
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 10.2.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-2370?
CVE-2017-2370 is considered a high severity vulnerability due to its potential for exploitation through a buffer overflow.
How do I fix CVE-2017-2370?
To fix CVE-2017-2370, users must update their affected Apple devices to the latest versions: iOS 10.2.1, macOS 10.12.3, watchOS 3.1.3, or tvOS 10.1.1.
Which products are affected by CVE-2017-2370?
CVE-2017-2370 affects Apple products including iOS before 10.2.1, macOS before 10.12.3, tvOS before 10.1.1, and watchOS before 3.1.3.
Can CVE-2017-2370 lead to remote code execution?
Yes, CVE-2017-2370 can potentially allow remote code execution on vulnerable Apple devices due to the buffer overflow.
What is the nature of the vulnerability in CVE-2017-2370?
CVE-2017-2370 is a buffer overflow issue that was addressed through improved memory handling within the kernel.