CVE-2021-30755Out-of-bounds Read in Apple Macos

CWE-125Out-of-bounds Read5 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.4%
top 38.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

NVDapple/tvos< 14.6
CVEListV5apple/macosunspecified11.4+2
NVDapple/macos11.011.4
NVDapple/watchos< 7.5
Appleapple/tvos14.6

🔴Vulnerability Details

1
GHSA
GHSA-gwjf-hjm7-xvq3: Processing a maliciously crafted font may result in the disclosure of process memory2022-05-24

📋Vendor Advisories

3
Apple
CVE-2021-30755: tvOS 14.62021-05-24
Apple
CVE-2021-30755: watchOS 7.52021-05-24
Apple
CVE-2021-30755: macOS Big Sur 11.42021-05-24