CVE-2021-1766
published 2021-04-02CVE-2021-1766: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.81%
52.9th percentile
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_14.4_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.4 | 14.4 |
| apple | ipados | < 14.4 | 14.4 |
| apple | iphone_os | < 14.4 | 14.4 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.14 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.2 | 11.2 |
| apple | macos | >= unspecified < 11.2 | 11.2 |
| apple | macos | >= unspecified < 7.3 | 7.3 |
| apple | macos | >= unspecified < 14.4 | 14.4 |
| apple | macos_big_sur_11.2_security_update_2021-001_catalina_security_update_2021-001_mo | — | — |
| apple | tvos | < 14.4 | 14.4 |
| apple | watchos | < 7.3 | 7.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rr24-55gg-g58c: This issue was addressed with improved checks
ghsa_unreviewed·2022-05-24
CVE-2021-1766 [MEDIUM] GHSA-rr24-55gg-g58c: This issue was addressed with improved checks
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44573 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap overflow vulnerabilities exist in oenSUSE libsolv through 13 Dec 2020 in the resolve_installed function at src/solver.c: line 1728 & 1766.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Apple
CVE-2021-1766: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
vendor_apple·2021-02-01·CVSS 5.5
CVE-2021-1766 [MEDIUM] CVE-2021-1766: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
Apple Security Update: About the security content of macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
Product: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
CVE: CVE-2021-1766
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: This issue was addressed with improved checks.
Apple
CVE-2021-1766: iOS 14.4 and iPadOS 14.4
vendor_apple·2021-01-26·CVSS 5.5
CVE-2021-1766 [MEDIUM] CVE-2021-1766: iOS 14.4 and iPadOS 14.4
Apple Security Update: About the security content of iOS 14.4 and iPadOS 14.4
Product: iOS 14.4 and iPadOS
Version: 14.4
CVE: CVE-2021-1766
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: This issue was addressed with improved checks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-44573 libsolv: Heap overflow
bugzilla·2022-02-22·CVSS 3.3
CVE-2021-44573 [LOW] CVE-2021-44573 libsolv: Heap overflow
CVE-2021-44573 libsolv: Heap overflow
Two heap overflow vulnerabilities exist in oenSUSE libsolv through 13 Dec 2020 in the resolve_installed function at src/solver.c: line 1728 & 1766.
https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_installed-1766
https://github.com/openSUSE/libsolv/issues/430
https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_installed-1728
Discussion:
Created libsolv tracking bugs for this issue:
Affects: fedora-all [bug 2056776]
---
Adding CVSS v3 from Red Hat.
Bugzilla
CVE-2021-34334 exiv2: Exiv2: Denial of Service via crafted image file
bugzilla·2021-08-10·CVSS 5.5
CVE-2021-34334 [MEDIUM] CVE-2021-34334 exiv2: Exiv2: Denial of Service via crafted image file
CVE-2021-34334 exiv2: Exiv2: Denial of Service via crafted image file
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.
Reference:
https://github.com/Exiv2/exiv2/security/advisories/GHSA-hqjh-hpv8-8r9p
Upstream patch:
https://github.com/Exiv2/exiv2/pull/1766
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1992204]
Created mingw-exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 199
https://support.apple.com/en-us/HT212146https://support.apple.com/en-us/HT212147https://support.apple.com/en-us/HT212148https://support.apple.com/en-us/HT212149https://support.apple.com/en-us/HT212146https://support.apple.com/en-us/HT212147https://support.apple.com/en-us/HT212148https://support.apple.com/en-us/HT212149
2021-04-02
Published