CVE-2016-4643
published 2019-01-11CVE-2016-4643: In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.21%
65.1th percentile
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_tv | < 9.2.2 | 9.2.2 |
| apple | ios | — | — |
| apple | iphone_os | < 9.3.3 | 9.3.3 |
| apple | mac_os | >= 10.11.0 < 10.11.6 | 10.11.6 |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| apple | tvos | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-4643: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 6.5
CVE-2016-4643 [MEDIUM] CVE-2016-4643: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4643
Component: CFNetwork Proxies
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
Apple
CVE-2016-4643: iOS 9.3.3
vendor_apple·2016-07-18·CVSS 6.5
CVE-2016-4643 [MEDIUM] CVE-2016-4643: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4643
Component: CFNetwork Proxies
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
Apple
CVE-2016-4643: tvOS 9.2.2
vendor_apple·2016-07-18·CVSS 6.5
CVE-2016-4643 [MEDIUM] CVE-2016-4643: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4643
Component: CFNetwork Proxies
Impact: An attacker in a privileged network position may be able to leak sensitive user information
Description: A validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
GHSA
GHSA-8jrg-2wj2-p7hp: In iOS before 9
ghsa_unreviewed·2022-05-14
CVE-2016-4643 [MEDIUM] CWE-200 GHSA-8jrg-2wj2-p7hp: In iOS before 9
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-01-11
Published