101691vdb entry
http://www.securityfocus.com/bid/101691 CVE-2017-13849
MEDIUM
iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
Record summary
CVE-2017-13849 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBiOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of ServiceExploitDB exploitby Russian OtterNot analyzed1 file
References
71039703vdb entry
http://www.securitytracker.com/id/1039703 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-13849 support.apple.comConfirmation
https://support.apple.com/HT208219 support.apple.comConfirmation
https://support.apple.com/HT208220 support.apple.comConfirmation
https://support.apple.com/HT208222 43161exploit
https://www.exploit-db.com/exploits/43161