CVE-2017-6975Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Iphone OS

Severity
6.8MEDIUMNVD
EPSS
0.1%
top 80.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 5
Latest updateMay 14

Description

Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom firmware functions, there is a separate CVE ID for the operating-system behavior.

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages3 packages

NVDapple/iphone_os10.3
Appleapple/ios10.3.1

🔴Vulnerability Details

1
GHSA
GHSA-4hvm-x6v7-c64m: Wi-Fi in Apple iOS before 102022-05-14

📋Vendor Advisories

2
Apple
CVE-2017-6975: Apple TV Software 7.32019-05-13
Apple
CVE-2017-6975: iOS 10.3.12017-04-03