Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crrf-7wcm-2c9m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

EPSS

Процентиль: 76%
0.00989
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость компонента ImageIO операционных систем Mac OS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 76%
0.00989
Низкий

Дефекты

CWE-787