CVE-2017-2418
published 2017-04-02CVE-2017-2418: An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest OS users to…
PriorityP425medium6.5CVSS 3.0
AVLACLPRLUINSCCHINAN
EPSS
0.34%
26.1th percentile
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest OS users to obtain sensitive information from the CR8 control register via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.12.3 | — |
| apple | macos_sierra_10.12.4_security_update_2017-001_el_capitan_and_security_update_201 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-2418: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
vendor_apple·2017-03-27·CVSS 6.5
CVE-2017-2418 [MEDIUM] CVE-2017-2418: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
Product: macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite
CVE: CVE-2017-2418
Component: Hypervisor
Impact: Applications using the Hypervisor framework may unexpectedly leak the CR8 control register between guest and host
Description: An information leakage issue was addressed through improved state management.
GHSA
GHSA-w25p-8q9j-g7j4: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-17
CVE-2017-2418 [MEDIUM] CWE-200 GHSA-w25p-8q9j-g7j4: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Hypervisor" component. It allows guest OS users to obtain sensitive information from the CR8 control register via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9265 openvswitch: Buffer over-read while parsing the group mod OpenFlow message
bugzilla·2017-05-31·CVSS 9.8
CVE-2017-9265 [CRITICAL] CVE-2017-9265 openvswitch: Buffer over-read while parsing the group mod OpenFlow message
CVE-2017-9265 openvswitch: Buffer over-read while parsing the group mod OpenFlow message
In Open vSwitch there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332965.html
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1456797]
---
This issue has been addressed in the following products:
Fast Datapath for RHEL 7
Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 9.0 (Mitaka)
Via RHSA-2017:2553 https://access.redhat.com/errata/RHSA-2017:2553
---
This issue h
Bugzilla
CVE-2017-9264 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
bugzilla·2017-05-31·CVSS 9.8
CVE-2017-9264 [CRITICAL] CVE-2017-9264 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
CVE-2017-9264 openvswitch: Buffer over-read while parsing malformed TCP, UDP and IPv6 packets
In lib/conntrack.c in the firewall implementation in Open vSwitch, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-March/329323.html
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1456797]
---
This issue has been addressed in the following products:
Fast Datapath for RHEL 7
Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 10.0 (Newton)
Via RH
Bugzilla
CVE-2017-9263 openvswitch: Invalid processing of a malicious OpenFlow role status message
bugzilla·2017-05-31·CVSS 6.5
CVE-2017-9263 [MEDIUM] CVE-2017-9263 openvswitch: Invalid processing of a malicious OpenFlow role status message
CVE-2017-9263 openvswitch: Invalid processing of a malicious OpenFlow role status message
In Open vSwitch while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332966.html
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1456797]
---
This issue has been addressed in the following products:
Fast Datapath for RHEL 7
Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 9.
Bugzilla
CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
bugzilla·2017-05-30·CVSS 9.8
CVE-2017-9214 [CRITICAL] CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
CVE-2017-9214 openvswitch: Integer underflow in the ofputil_pull_queue_get_config_reply10 function
A vulnerability in openvswitch was found. While parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
References:
https://mail.openvswitch.org/pipermail/ovs-dev/2017-May/332711.html
Discussion:
Created openvswitch tracking bugs for this issue:
Affects: fedora-all [bug 1456797]
---
This issue has been addressed in the following products:
Fast Datapath for RHEL 7
Via RHSA-2017:2418 https://access.redhat.com/errata/RHSA-2017:2418
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 9.0 (Mita
2017-04-02
Published