CVE-2024-44144Classic Buffer Overflow in Apple IOS AND Ipados

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 94.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28

Description

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

CVEListV5apple/macos< 14.7.1+1
NVDapple/macos< 14.7.1
NVDapple/ipados< 17.7.1
CVEListV5apple/ios_and_ipados< 17.7.1+1
CVEListV5apple/tvos< 18

🔴Vulnerability Details

2
CVEList
CVE-2024-44144: A buffer overflow was addressed with improved size validation2024-10-28
GHSA
GHSA-m7jf-xm88-cv45: A buffer overflow was addressed with improved size validation2024-10-28

📋Vendor Advisories

7
Apple
CVE-2024-44144: iOS 17.7.1 and iPadOS 17.7.12024-10-28
Apple
CVE-2024-44144: macOS Sonoma 14.7.12024-10-28
Apple
CVE-2024-44144: iOS 18 and iPadOS 182024-09-16
Apple
CVE-2024-44144: watchOS112024-09-16
Apple
CVE-2024-44144: visionOS22024-09-16
CVE-2024-44144 — Classic Buffer Overflow in Apple | cvebase