First published: Thu Jul 20 2017(Updated: )
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
iStyle @cosme iPhone OS | <=10.3.2 | |
Apple iOS and macOS | <=10.12.5 | |
tvOS | <=10.2.1 | |
Apple iOS, iPadOS, and watchOS | <=3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7068 is classified as a high severity vulnerability that could allow remote attackers to execute arbitrary code.
To fix CVE-2017-7068, users should update their affected Apple products to the latest versions of iOS, macOS, tvOS, and watchOS.
CVE-2017-7068 affects iOS versions before 10.3.3, macOS versions before 10.12.6, tvOS versions before 10.2.2, and watchOS versions before 3.2.3.
The vulnerability in CVE-2017-7068 involves the 'libarchive' component.
Yes, CVE-2017-7068 can potentially allow attackers to cause a denial of service on affected Apple devices.