CVE-2017-2426: Infoleak
Published Apr 2, 2017
·Updated
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "iBooks" component. It allows remote attackers to obtain sensitive information from local files via a file: URL in an iBooks file.
Affected Software
1 affected component
Apple iOS and macOS<=10.12.3
Event History
Apr 2, 2017
CVE Published
via MITRE·01:36 AM
Data Sourced
via MITRE·01:36 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Jun 17, 58461
Event
06:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-2426?
CVE-2017-2426 has a medium severity rating, allowing attackers to obtain sensitive information.
2
How do I fix CVE-2017-2426?
To mitigate CVE-2017-2426, upgrade to macOS 10.12.4 or later.
3
What products are affected by CVE-2017-2426?
macOS versions prior to 10.12.4 are affected by CVE-2017-2426.
4
What type of attack is associated with CVE-2017-2426?
CVE-2017-2426 involves remote attackers exploiting a vulnerability in the iBooks component.
5
Can CVE-2017-2426 lead to data exposure?
Yes, CVE-2017-2426 can lead to the exposure of sensitive information from local files.