CVE-2016-1850
published 2016-05-20CVE-2016-1850: SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
PriorityP336high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.21%
80.8th percentile
SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.4 | — |
| apple | os_x_el_capitan_v10.11.5_and_security_update_2016-003 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-1850: OS X El Capitan v10.11.5 and Security Update 2016-003
vendor_apple·CVSS 7.8
CVE-2016-1850 [HIGH] CVE-2016-1850: OS X El Capitan v10.11.5 and Security Update 2016-003
Apple Security Update: About the security content of OS X El Capitan v10.11.5 and Security Update 2016-003
Product: OS X El Capitan v10.11.5 and Security Update 2016-003
CVE: CVE-2016-1850
Component: CVE-ID
GHSA
GHSA-7gg2-vwgx-8wmw: SceneKit in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-1850 [HIGH] CWE-119 GHSA-7gg2-vwgx-8wmw: SceneKit in Apple OS X before 10
SceneKit in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Apple Remote Code Execution With Image Files
blogs_talos·2016-07-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Apple Remote Code Execution With Image Files
Vulnerabilities discovered by Tyler Bohan of Cisco Talos.
Many of the wide variety of file formats are designed for specialized uses within specific industries. Apple offers APIs as interfaces to provide a definitive way to access image data for multiple image formats on the Apple OS X platform. Talos is disclosing the presence of five remote code execution vulnerabilities in Apple OS X related to processing image formats: TALOS-2016-0171, TALOS-2016-0180,TALOS-2016-0181, TALOS-2016-0183, TALOS-2016-186.
## TALOS-2016-0171
### Tagged Image File Format (TIFF) (CVE-2016-4631)
The Tagged Image File Format (TIFF) is a file format that is popular with graphic artists, photographers and the publishing industry because of its ability to store images in a lossless format. TIFF was created to t
Talos
Vulnerability Spotlight: Apple Remote Code Execution With Image Files
blogs_talos·2016-07-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Apple Remote Code Execution With Image Files
## Vulnerability Spotlight: Apple Remote Code Execution With Image Files
Vulnerabilities discovered by Tyler Bohan of Cisco Talos.
Many of the wide variety of file formats are designed for specialized uses within specific industries. Apple offers APIs as interfaces to provide a definitive way to access image data for multiple image formats on the Apple OS X platform. Talos is disclosing the presence of five remote code execution vulnerabilities in Apple OS X related to processing image formats: TALOS-2016-0171, TALOS-2016-0180,TALOS-2016-0181, TALOS-2016-0183, TALOS-2016-186.
## TALOS-2016-0171
## Tagged Image File Format (TIFF) (CVE-2016-4631)
The Tagged Image File Format (TIFF) is a file format that is popular with graphic artists, photographers and the publishing industry because o
Bugzilla
CVE-2015-8932 libarchive: Undefined behavior / invalid shiftleft in TAR parser
bugzilla·2016-06-22·CVSS 5.5
CVE-2015-8932 [MEDIUM] CVE-2015-8932 libarchive: Undefined behavior / invalid shiftleft in TAR parser
CVE-2015-8932 libarchive: Undefined behavior / invalid shiftleft in TAR parser
Undefined behaviour (invalid left shift) was discovered in libarchive,
in how Compress streams are identified. This could cause certain
files to be mistakenly identified as Compress archives and fail to read.
Upstream bug:
https://github.com/libarchive/libarchive/issues/547
Upstream fix:
https://github.com/libarchive/libarchive/commit/f0b1dbb
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
Affects: epel-5 [bug 1352775]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1850 https://rhn.redhat.com/errata/RHSA-2016-1850.html
---
This issue has been addressed in the following products:
Red Hat Enterprise L
Bugzilla
CVE-2015-8920 libarchive: Stack out of bounds read in ar parser
bugzilla·2016-06-21·CVSS 5.5
CVE-2015-8920 [MEDIUM] CVE-2015-8920 libarchive: Stack out of bounds read in ar parser
CVE-2015-8920 libarchive: Stack out of bounds read in ar parser
Upstream bug:
https://github.com/libarchive/libarchive/issues/511
Upstream fix:
https://github.com/libarchive/libarchive/commit/97f964e
> While pruning trailing text from ar filenames, we did not
> check for an empty filename. This results in reading the
> byte before the filename on the stack.
Discussion:
Created libarchive tracking bugs for this issue:
Affects: fedora-all [bug 1352776]
Affects: epel-5 [bug 1352775]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1850 https://rhn.redhat.com/errata/RHSA-2016-1850.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1844 https://rhn.redhat.com/errata/RHSA-20
Bugzilla
CVE-2016-7166 libarchive: Denial of service using a crafted gzip file
bugzilla·2016-06-16·CVSS 5.5
CVE-2016-7166 [MEDIUM] CVE-2016-7166 libarchive: Denial of service using a crafted gzip file
CVE-2016-7166 libarchive: Denial of service using a crafted gzip file
A specially crafted gzip file can cause libarchive to allocate memory
without limit, eventually leading to a crash.
External references:
https://github.com/libarchive/libarchive/issues/660
Upstream fix:
https://github.com/libarchive/libarchive/commit/6e06b1c89
Discussion:
Created libarchive tracking bugs for this issue:
Affects: epel-5 [bug 1352775]
Affects: fedora-all [bug 1352776]
---
FTR: Not back-porting follow-up patch 37649d274867edd2dd25d8a3057c3b6cd81ce83e
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1850 https://rhn.redhat.com/errata/RHSA-2016-1850.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Bugzilla
CVE-2016-4809 libarchive: Memory allocate error with symbolic links in cpio archives
bugzilla·2016-06-16·CVSS 7.5
CVE-2016-4809 [HIGH] CVE-2016-4809 libarchive: Memory allocate error with symbolic links in cpio archives
CVE-2016-4809 libarchive: Memory allocate error with symbolic links in cpio archives
A cpio archive with a ridiculously large symlink can cause memory allocation
to fail, resulting in any attempt to view or extract the archive crashing.
The failed allocation appears to be handled correctly within libarchive and
not lead to further issues.
External references:
https://github.com/libarchive/libarchive/issues/705
Upstream fix:
https://github.com/libarchive/libarchive/commit/fd7e0c02
Discussion:
Created libarchive tracking bugs for this issue:
Affects: epel-5 [bug 1352775]
Affects: fedora-all [bug 1352776]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1850 https://rhn.redhat.com/errata/RHSA-2016-1850.html
---
This issue has be
http://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securityfocus.com/bid/90696http://www.securitytracker.com/id/1035895https://support.apple.com/HT206567http://lists.apple.com/archives/security-announce/2016/May/msg00004.htmlhttp://www.securityfocus.com/bid/90696http://www.securitytracker.com/id/1035895https://support.apple.com/HT206567
2016-05-20
Published