CVE-2023-23494Classic Buffer Overflow in Apple IOS AND Ipados

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 40.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8

Description

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages4 packages

NVDapple/ipados< 16.4
CVEListV5apple/ios_and_ipadosunspecified16.4
NVDapple/iphone_os< 16.4

🔴Vulnerability Details

1
GHSA
GHSA-mv7q-44hp-2xp6: A buffer overflow was addressed with improved bounds checking2023-05-08

📋Vendor Advisories

1
Apple
CVE-2023-23494: iOS 16.4 and iPadOS 16.42023-03-27