First published: Tue Aug 24 2021(Updated: )
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Unpacking a maliciously crafted archive may lead to arbitrary code execution.
Credit: Simon Huang @HuangShaomang pjf IceSword Lab of Qihoo 360Simon Huang @HuangShaomang pjf IceSword Lab of Qihoo 360Simon Huang @HuangShaomang pjf IceSword Lab of Qihoo 360Simon Huang @HuangShaomang pjf IceSword Lab of Qihoo 360Simon Huang @HuangShaomang pjf IceSword Lab of Qihoo 360Simon Huang @HuangShaomang pjf IceSword Lab of Qihoo 360 cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <15.1 | 15.1 |
Apple iPadOS | <15.1 | 15.1 |
Apple macOS Monterey | <12.0.1 | 12.0.1 |
Apple Catalina | ||
Apple macOS Big Sur | <11.6.1 | 11.6.1 |
Apple watchOS | <8.1 | 8.1 |
Apple tvOS | <15.1 | 15.1 |
Apple iPadOS | <15.1 | |
Apple iPhone OS | <15.1 | |
Apple Mac OS X | <10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-004 | |
Apple Mac OS X | =10.15.7-security_update_2021-005 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.6.1 | |
Apple macOS | =12.0 | |
Apple tvOS | <15.1 | |
Apple watchOS | <8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30881 is a vulnerability in FileProvider that involves an input validation issue with improved memory handling.
CVE-2021-30881 affects users of Apple products running specific versions of macOS, iOS, iPadOS, watchOS, and tvOS.
To protect yourself from CVE-2021-30881, make sure to update your Apple devices to the recommended versions mentioned in the vulnerability description.
More information about CVE-2021-30881 can be found on the official Apple support page listed in the references section.
The CWE ID for CVE-2021-30881 is CWE-20, which corresponds to input validation issues.