CVE-2017-2417

MEDIUM

Apple <10.3, <10.12.4, <10.2, <3.2 - DoS

Title source: llm

Description

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to cause a denial of service (infinite recursion) via a crafted image.

Scores

CVSS v3 5.5
EPSS 0.0055
EPSS Percentile 67.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-835
Status published

Affected Products (5)

apple/iphone_os < 10.2.1
apple/mac_os_x < 10.12.3
apple/tvos < 10.1.1
apple/watchos < 3.1.3
n/a/n/a

Timeline

Published Apr 02, 2017
Tracked Since Feb 18, 2026