Vulnerability Name: | CVE-2021-30942 (CCN-215079) | ||||||||||||
Assigned: | 2021-08-24 | ||||||||||||
Published: | 2021-08-24 | ||||||||||||
Updated: | 2022-04-01 | ||||||||||||
Summary: | Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
7.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-787 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-30942 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/165559/Apple-ColorSync-Out-Of-Bounds-Read.html Source: XF Type: UNKNOWN appleios-cve202130942-code-exec(215079) Source: CCN Type: Packet Storm Security [01-13-2022] Apple ColorSync Out-Of-Bounds Read Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT212975 Source: CCN Type: Apple security document HT212976 About the security content of iOS 15.2 and iPadOS 15.2 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT212976 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT212978 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT212979 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT212980 Source: MISC Type: Vendor Advisory https://support.apple.com/en-us/HT212981 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |