CVE-2021-1857

CWE-6657 documents5 sources
Severity
6.5MEDIUM
EPSS
0.6%
top 30.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages14 packages

CVEListV5apple/icloud_for_windowsunspecified12.3
CVEListV5apple/itunes_for_windowsunspecified12.11
CVEListV5apple/tvosunspecified14.5
NVDapple/tvos< 14.5
CVEListV5apple/macosunspecified11.3+1

🔴Vulnerability Details

2
GHSA
GHSA-gr6c-576g-h3q2: A memory initialization issue was addressed with improved memory handling2022-05-24
CVEList
CVE-2021-1857: A memory initialization issue was addressed with improved memory handling2021-09-08

📋Vendor Advisories

4
Chrome
Stable Channel Update for Desktop: CVE-2022-18562022-05-24
Apple
CVE-2021-1857: iOS 14.5 and iPadOS 14.52021-04-26
Apple
CVE-2021-1857: Security Update 2021-002 Catalina2021-04-26
Apple
CVE-2021-1857: macOS Big Sur 11.32021-04-26
CVE-2021-1857 (MEDIUM CVSS 6.5) | A memory initialization issue was a | cvebase.io