CVE-2017-13865: Infoleak
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Other sources
Kernel. A validation issue was addressed with improved input sanitization.
Kernel. Multiple validation issues were addressed with improved input sanitization.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7164
- CVE-2017-13905
- CVE-2017-7172
- CVE-2017-7171
- CVE-2017-7151
- CVE-2017-7162
- CVE-2017-13861
- CVE-2017-13904
- CVE-2017-5754
- CVE-2017-13862
- CVE-2017-13867
- CVE-2017-13876
- CVE-2017-7173
- CVE-2017-13855
- CVE-2017-13865
- CVE-2017-13868
- CVE-2017-13869
- CVE-2017-7154
- CVE-2017-13885
- CVE-2017-7165
- CVE-2017-13884
- CVE-2017-7153
- CVE-2017-7156
- CVE-2017-7157
- CVE-2017-13856
- CVE-2017-13870
- CVE-2017-7160
- CVE-2017-13866
- CVE-2017-13080
- CVE-2017-13887
- CVE-2017-9798
- CVE-2017-13892
- CVE-2017-1000254
- CVE-2017-13872
- CVE-2017-15422
- CVE-2017-13883
- CVE-2017-7163
- CVE-2017-7155
- CVE-2017-13878
- CVE-2017-13875
- CVE-2017-7159
- CVE-2017-13848
- CVE-2017-13858
- CVE-2017-13847
- CVE-2017-13871
- CVE-2017-13860
- CVE-2017-3735
- CVE-2017-12837
- CVE-2017-7158
- CVE-2017-13911
- CVE-2017-13886
- CVE-2017-13880
- CVE-2017-2411
- CVE-2017-13879
- CVE-2017-13874
- CVE-2017-7152
- CVE-2017-13888
- CVE-2017-13891
Frequently Asked Questions
What is the severity of CVE-2017-13865?
The severity of CVE-2017-13865 is medium with a severity value of 5.5.
Which Apple products are affected by CVE-2017-13865?
iOS before 11.2, macOS before 10.13.2, tvOS before 11.2, and watchOS before 4.2 are affected by CVE-2017-13865.
What is the issue addressed in CVE-2017-13865?
CVE-2017-13865 is a validation issue that was addressed with improved input sanitization.
How can attackers exploit CVE-2017-13865?
Attackers can exploit CVE-2017-13865 to bypass intended memory-read restrictions via a crafted app.
Is there a remedy available for CVE-2017-13865?
Yes, the remedy for CVE-2017-13865 is to update to the specified versions of the affected software.