← Zuruck zu CVEs
CVE-2021-30942
HIGH7.8
Beschreibung
Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
CVE Details
CVSS v3.1 Bewertung7.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht8/24/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
apple:ipadosapple:iphone_osapple:mac_os_xapple:macosapple:tvosapple:watchos
Schwachen (CWE)
CWE-787
Referenzen
http://packetstormsecurity.com/files/165559/Apple-ColorSync-Out-Of-Bounds-Read.html(product-security@apple.com)
https://support.apple.com/en-us/HT212975(product-security@apple.com)
https://support.apple.com/en-us/HT212976(product-security@apple.com)
https://support.apple.com/en-us/HT212978(product-security@apple.com)
https://support.apple.com/en-us/HT212979(product-security@apple.com)
https://support.apple.com/en-us/HT212980(product-security@apple.com)
https://support.apple.com/en-us/HT212981(product-security@apple.com)
http://packetstormsecurity.com/files/165559/Apple-ColorSync-Out-Of-Bounds-Read.html(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212975(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212976(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212978(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212979(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212980(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/en-us/HT212981(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.