CVE-2017-2391
published 2017-04-02CVE-2017-2391: An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before…
PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
0.96%
57.4th percentile
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | keynote | <= 7.0.5 | — |
| apple | keynote | <= 3.0.5 | — |
| apple | numbers | <= 4.0.5 | — |
| apple | numbers | <= 3.0.5 | — |
| apple | pages | <= 6.0.5 | — |
| apple | pages | <= 3.0.5 | — |
| apple | pages_6.1_numbers_4.1_and_keynote_7.1_for_mac_and_pages_3.1_numbers_3.1_and_keyn | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-2391: Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac and Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS
vendor_apple·2017-03-27·CVSS 5.3
CVE-2017-2391 [MEDIUM] CVE-2017-2391: Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac and Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS
Apple Security Update: About the security content of Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac and Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS
Product: Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac and Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS
CVE: CVE-2017-2391
Component: Export
Impact: The contents of password-protected PDFs exported from iWork may be exposed
Description: iWork used weak 40-bit RC4 encryption for password-protected PDF exports. This issue was addressed by changing iWork export to use AES-128.
GHSA
GHSA-7w6p-v52h-gg48: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-17
CVE-2017-2391 [MEDIUM] CWE-326 GHSA-7w6p-v52h-gg48: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/97126http://www.securitytracker.com/id/1038134http://www.securitytracker.com/id/1038135http://www.securitytracker.com/id/1038136https://support.apple.com/HT207595http://www.securityfocus.com/bid/97126http://www.securitytracker.com/id/1038134http://www.securitytracker.com/id/1038135http://www.securitytracker.com/id/1038136https://support.apple.com/HT207595
2017-04-02
Published