First published: Thu Jul 20 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Audio" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted audio file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7015 has a medium severity rating as it can lead to information disclosure or denial of service.
To fix CVE-2017-7015, update your macOS to version 10.12.6 or later.
CVE-2017-7015 affects macOS versions prior to 10.12.6.
CVE-2017-7015 is a vulnerability in the audio component that can lead to remote information leakage or a denial of service.
Yes, CVE-2017-7015 can be exploited remotely through the use of crafted audio files.