CVE Vulnerabilities

CVE-2023-42888

Published: Jan 23, 2024 | Modified: Jan 26, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.

Affected Software

Name Vendor Start Version End Version
Ipados Apple 16.0 (excluding) 16.7.5 (excluding)
Ipados Apple 17.0 (excluding) 17.2 (excluding)
Iphone_os Apple 16.0 (excluding) 16.7.5 (excluding)
Iphone_os Apple 17.0 (excluding) 17.2 (excluding)
Macos Apple 12.0 (including) 12.7.3 (excluding)
Macos Apple 13.0 (including) 13.6.4 (excluding)
Macos Apple 14.0 (including) 14.2 (excluding)
Watchos Apple * 10.2 (excluding)

References