CISA KEV 정보
| 취약점명 | Apple Multiple Products Integer Overflow Vulnerability |
|---|---|
| 설명 | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-20 | CWE-190 |
| 등록일 (KEV) | 2021-11-03 |
| 조치 기한 | 2021-11-17 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2021-30860 |
NVD 상세 정보
CVSS v3.1: 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS v2.0: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P설명: An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CWE: CWE-190 | CWE-190
참조
- http://seclists.org/fulldisclosure/2021/Sep/25 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/26 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/27 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/28 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/38 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/39 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/40 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2021/Sep/50 [Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2022/09/02/11 [Mailing List]
- https://security.gentoo.org/glsa/202209-21 [Third Party Advisory]
- https://support.apple.com/en-us/HT212804 [Vendor Advisory]
- https://support.apple.com/en-us/HT212805 [Vendor Advisory]
- https://support.apple.com/en-us/HT212806 [Vendor Advisory]
- https://support.apple.com/en-us/HT212807 [Vendor Advisory]
- https://support.apple.com/kb/HT212824 [Vendor Advisory]
- ... 외 16건
This product uses the NVD API but is not endorsed or certified by the NVD.