seclists.org
http://seclists.org/fulldisclosure/2023/Dec/12 CVE-2023-42916
MEDIUMCISA KEV
Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Record summary
CVE-2023-42916 has a selected CVSS score of 6.5 (medium). CISA lists CVE-2023-42916 in KEV.
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Dec 4, 2023 · CISA
- VulnCheck KEV
- Listed · Nov 30, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 2, 2023 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
SafariBrowse Apple / SafariDefault status: unknown | CVE List | Before 17.1 | affected |
| Before 17.1.2 | affected | ||
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 17.1 | affected |
macOSBrowse Apple / macOSDefault status: unknown | CVE List | Before 14.1 | affected |
| 14.0.0 to < 14.1.2 | affected | ||
ipadosBrowse apple / ipadosDefault status: unknown | CVE List | Before 17.1.2 | affected |
iphone_osBrowse apple / iphone_osDefault status: unknown | CVE List | Before 17.1.2 | affected |
References
Showing 12 of 20seclists.org
http://seclists.org/fulldisclosure/2023/Dec/13 seclists.org
http://seclists.org/fulldisclosure/2023/Dec/3 seclists.org
http://seclists.org/fulldisclosure/2023/Dec/4 seclists.org
http://seclists.org/fulldisclosure/2023/Dec/5 seclists.org
http://seclists.org/fulldisclosure/2023/Dec/8 seclists.org
http://seclists.org/fulldisclosure/2024/Jan/35 openwall.com
http://www.openwall.com/lists/oss-security/2023/12/05/1 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AD2KIHHCUBQC2YYH3FJWAHI5BG3QETOH lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P5LQS6VEI7VIZNC7QGQ62EOV45R5RJIR nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-42916 security.gentoo.org
https://security.gentoo.org/glsa/202401-04