Record summary

CVE-2017-13849 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBiOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of ServiceExploitDB exploitby Russian OtterNot analyzed1 file
ExploitDB

PoC details

References

7