CVE-2016-1830
published 2016-05-20CVE-2016-1830: The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a…
PriorityP336high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.35%
68.8th percentile
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1828, and CVE-2016-1829.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 9.3.2 | 9.3.2 |
| apple | mac_os_x | < 10.11.5 | 10.11.5 |
| apple | os_x_el_capitan_v10.11.5_and_security_update_2016-003 | — | — |
| apple | tvos | < 9.2.1 | 9.2.1 |
| apple | tvos | — | — |
| apple | watchos | < 2.2.1 | 2.2.1 |
| apple | watchos | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h8j4-x589-fv2p: The kernel in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2016-1829 [HIGH] CWE-119 GHSA-h8j4-x589-fv2p: The kernel in Apple iOS before 9
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1828, and CVE-2016-1830.
GHSA
GHSA-wpq6-226c-pxw4: The kernel in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2016-1827 [HIGH] CWE-119 GHSA-wpq6-226c-pxw4: The kernel in Apple iOS before 9
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1828, CVE-2016-1829, and CVE-2016-1830.
GHSA
GHSA-jm76-99qf-596j: The kernel in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2016-1828 [HIGH] CWE-119 GHSA-jm76-99qf-596j: The kernel in Apple iOS before 9
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.
GHSA
GHSA-768f-8465-rm78: The kernel in Apple iOS before 9
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2016-1830 [HIGH] CWE-119 GHSA-768f-8465-rm78: The kernel in Apple iOS before 9
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1828, and CVE-2016-1829.
Apple
CVE-2016-1830: watchOS 2.2.1
vendor_apple·CVSS 7.8
CVE-2016-1830 [HIGH] CVE-2016-1830: watchOS 2.2.1
Apple Security Update: About the security content of watchOS 2.2.1
Product: watchOS
Version: 2.2.1
CVE: CVE-2016-1830
Component: CVE-ID
Impact: A local attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
Apple
CVE-2016-1830: OS X El Capitan v10.11.5 and Security Update 2016-003
vendor_apple·CVSS 7.8
CVE-2016-1830 [HIGH] CVE-2016-1830: OS X El Capitan v10.11.5 and Security Update 2016-003
Apple Security Update: About the security content of OS X El Capitan v10.11.5 and Security Update 2016-003
Product: OS X El Capitan v10.11.5 and Security Update 2016-003
CVE: CVE-2016-1830
Component: CVE-ID
Apple
CVE-2016-1830: iOS 9.3.2
vendor_apple·CVSS 7.8
CVE-2016-1830 [HIGH] CVE-2016-1830: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1830
Component: CVE-ID
Impact: A local attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
Apple
CVE-2016-1830: tvOS 9.2.1
vendor_apple·CVSS 7.8
CVE-2016-1830 [HIGH] CVE-2016-1830: tvOS 9.2.1
Apple Security Update: About the security content of tvOS 9.2.1
Product: tvOS
Version: 9.2.1
CVE: CVE-2016-1830
Component: CVE-ID
Impact: An application may be able to cause unexpected application termination or arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
bugzilla·2016-05-24·CVSS 5.0
CVE-2016-3088 [MEDIUM] CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
CVE-2016-3088 activemq: Fileserver web application vulnerability allowing RCE
Multiple vulnerabilities have been identified in the Apache ActiveMQ Fileserver web application. These are similar to those reported in CVE-2015-1830 and can allow attackers to replace web application files with malicious code and perform remote code execution on the system.
Mitigation:
Users are advised to use other FTP and HTTP based file servers for transferring blob messages. Fileserver web application SHOULD NOT be used in older version of the broker and it should be disabled (it has been disabled by default since 5.12.0). This can be done by removing (commenting out) the following lines from conf\jetty.xml file
External Reference:
http://activemq.apache.org/security-advisories.data/CVE-2016-3088
Bugzilla
CVE-2016-3108 pulp: Insecure temporary file used when generating certificate for Pulp Nodes
bugzilla·2016-04-11·CVSS 7.1
CVE-2016-3108 [HIGH] CVE-2016-3108 pulp: Insecure temporary file used when generating certificate for Pulp Nodes
CVE-2016-3108 pulp: Insecure temporary file used when generating certificate for Pulp Nodes
It was reported that pulp-gen-nodes-certificate script uses insecurely created temporary files for storing the generated node certificates, allowing local attackers to leak the keys or overwrite arbitrary file via symlink.
Discussion:
Acknowledgments:
Name: Jeremy Cline (Red Hat), Sander Bos
---
Created attachment 1145990
Proposed patch
---
Created attachment 1146475
Proposed patch
I am attaching a revised version of the patch that removes the unneeded umask statement, and credits jcline in the commit message.
---
This is reported upstream as #1830 and is fixed by PR #2528:
https://pulp.plan.io/issues/1830
https://github.com/pulp/pulp/pull/2528
---
The Pulp upstream bug status is at CL
http://lists.apple.com/archives/security-announce/2016/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securityfocus.com/bid/90691http://www.securitytracker.com/id/1035890https://support.apple.com/HT206564https://support.apple.com/HT206566https://support.apple.com/HT206567https://support.apple.com/HT206568http://lists.apple.com/archives/security-announce/2016/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securityfocus.com/bid/90691http://www.securitytracker.com/id/1035890https://support.apple.com/HT206564https://support.apple.com/HT206566https://support.apple.com/HT206567https://support.apple.com/HT206568
2016-05-20
Published