Apple iOS and tvOS CVE-2017-14315 Heap Based Buffer Overflow Vulnerability
BID:100816
CVE-2017-14315 |Info
Apple iOS and tvOS CVE-2017-14315 Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 100816 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-14315 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2017 12:00AM |
| Updated: | Sep 12 2017 12:00AM |
| Credit: | Ben Seri and Gregory Vishnepolsky of Armis |
| Vulnerable: |
Apple tvOS 0 Apple TV 0 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 9.3.4 Apple iOS 9.3.3 Apple iOS 9.3.2 Apple iOS 9.3.1 Apple iOS 9.2.1 Apple iOS 9.0.2 Apple iOS 9.0.1 Apple iOS 8.4.1 Apple iOS 7.2 Apple iOS 7.0.6 Apple iOS 7.0.5 Apple iOS 7.0.3 Apple iOS 7.0.2 Apple iOS 7.0.1 Apple iOS 9.3.5 Apple iOS 9.3 Apple iOS 9.2 Apple iOS 9.1 Apple iOS 9 Apple iOS 8.4 Apple iOS 8.3 Apple iOS 8.2 Apple iOS 8.1.3 Apple iOS 8.1.2 Apple iOS 8.1.1 Apple iOS 8.1 Apple iOS 8 Apple iOS 7.1.2 Apple iOS 7.1.1 Apple iOS 7.1 Apple iOS 7.0.4 Apple iOS 7 |
| Not Vulnerable: | |
Discussion
Apple iOS and tvOS CVE-2017-14315 Heap Based Buffer Overflow Vulnerability
Apple iOS and tvOS are prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial of service conditions.
Following products and versions are vulnerable:
Apple iOS 7 through 9.3.5
Apple tvOS
Apple iOS and tvOS are prone to a heap-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial of service conditions.
Following products and versions are vulnerable:
Apple iOS 7 through 9.3.5
Apple tvOS
Exploit / POC
Apple iOS and tvOS CVE-2017-14315 Heap Based Buffer Overflow Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
Apple iOS and tvOS CVE-2017-14315 Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apple iOS and tvOS CVE-2017-14315 Heap Based Buffer Overflow Vulnerability
References:
References:
- Apple iOS Homepage (Apple)
- Apple TV Homepage (Apple)
- Apple tvOS - Homepage (Apple)
- The dangers of Bluetooth implementations: Unveiling zero day vulnerabilities (Ben Seri ??& Gregory Vishnepolsky)
- The IoT Attack Vector �??BlueBorne�?� Exposes Almost Every Connected Device (Armis)
- VU#240311 Multiple Bluetooth implementation vulnerabilities affect many devices (CERT)