Vulnerability CVE-2016-1788


Published: 2016-03-23   Modified: 2016-03-24

Description:
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachments via vectors related to duplicate messages.

CVSS2 => (AV:N/AC:H/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.6/10
2.9/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Apple -> Iphone os 
Apple -> Mac os x 
Apple -> Watchos 

 References:
https://support.apple.com/HT206168
https://support.apple.com/HT206167
https://support.apple.com/HT206166
http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html
http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html

Copyright 2024, cxsecurity.com

 

Back to Top