vendor:
iOS
by:
Maksymilian Arciemowicz
7,5
CVSS
HIGH
Remote memory corruption
119
CWE
Product Name: iOS
Affected Version From: iOS 10.1.x
Affected Version To: iOS 10.1.x
Patch Exists: YES
Related CWE: N/A
CPE: apple:ios:10.1.x
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apple Mail, Safari Mobile
2016
iOS 10.1.x Remote memory corruption through certificate file
Special crafted certificate file may lead to memory corruption of several processes and the vector attack may be through Mobile Safari or Mail app. Attacker may control the overflow through the certificate length in OCSP field.
Mitigation:
Disable the use of untrusted certificates and ensure that all certificates are up-to-date.