7.8
CVSSv3

CVE-2017-13833

Published: 13/11/2017 Updated: 29/04/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in certain Apple products. macOS prior to 10.13.1 is affected. The issue involves the "CFNetwork" component. It allows malicious users to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

Github Repositories

CVE-2017-7173: Local denial of service for iOS requiring root privileges.

sysctl_coalition_get_pid_list-dos The sysctl_coalition_get_pid_list function in bsd/kern/sys_coalitionc uses the coalition_get_pid_list function to collect a list of PIDs in a coalition This function will return the number of PIDs if successful or a negative errno on failure However, the sysctl_coalition_get_pid_list function does not properly check for the error condition,