Описание
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted font file.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.13.0 (включая)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00518
Низкий
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted font file.
EPSS
Процентиль: 66%
0.00518
Низкий
7.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-400