First published: Mon Sep 25 2017(Updated: )
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Credit: product-security@apple.com found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <=10.12.6 | |
Apple macOS High Sierra | <10.13 | 10.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7125 is a vulnerability in certain Apple products that allows remote attackers to cause a denial of service or have other unspecified impact.
macOS before 10.13 and the third-party "file" product versions before 5.30 are affected by CVE-2017-7125.
CVE-2017-7125 has a severity rating of 9.8 (critical).
To fix CVE-2017-7125, update to macOS version 10.13 or later and update the third-party "file" product to version 5.30 or later.
More information about CVE-2017-7125 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/100993), [Apple Support](https://support.apple.com/HT208144), [Apple Support](https://support.apple.com/en-us/HT208144).