CVE-2016-1782Improper Access Control in Apple Iphone OS

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 27.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 14

Description

WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDapple/safari9.0.3
Appleapple/safari9.1
NVDapple/iphone_os9.2.1
Appleapple/ios9.3

🔴Vulnerability Details

2
GHSA
GHSA-q6q9-w26g-c8vj: WebKit in Apple iOS before 92022-05-14
OSV
CVE-2016-1782: WebKit in Apple iOS before 92016-03-24

📋Vendor Advisories

2
Apple
CVE-2016-1782: Safari 9.1
Apple
CVE-2016-1782: iOS 9.3

💬Community

1
Bugzilla
Port banning can be bypassed with 30x redirect2016-01-04
CVE-2016-1782 — Improper Access Control in Apple | cvebase