Vulnerability CVE-2016-7636


Published: 2017-02-20

Description:
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows man-in-the-middle attackers to cause a denial of service (application crash) via vectors related to OCSP responder URLs.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Apple macOS 10.12.1/iOS 10 SecureTransport SSL handshake OCSP MiTM and DoS
Maksymilian Arci...
22.10.2016

Type:

CWE-20

(Improper Input Validation)

Vendor: Apple
Product: Watch os 
Version: 3.1.1;
Product: Watchos 
Version: 2.2.2;
Product: Mac os x 
Version: 10.12.1;
Product: Iphone os 
Version: 10.1.1;

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.securityfocus.com/bid/94905
http://www.securitytracker.com/id/1037469
https://support.apple.com/HT207422
https://support.apple.com/HT207423
https://support.apple.com/HT207487

Related CVE
CVE-2018-4404
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.
CVE-2018-4330
In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.
CVE-2018-4298
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permissions issue existed in Remote Management. This issue was addressed through improved permission validation.
CVE-2018-4281
In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation.
CVE-2018-4278
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tr...
CVE-2018-4277
In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
CVE-2018-4262
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
CVE-2018-4258
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.

Copyright 2019, cxsecurity.com

 

Back to Top