CVE-2021-30917: Input Validation
Published Aug 24, 2021
·Updated
ColorSync. A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation.
Credit
Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero), Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero), Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero), Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero), Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero), Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero), Alexandru-Vlad Niculae, Mateusz Jurczyk(Google Project Zero)
Affected Software
27 affected componentsFixes available
Apple macOS Big Sur<11.6.1
11.6.1
Apple tvOS<15.1
15.1
Apple Catalina
Apple WatchOS<8.1
8.1
Apple macOS Monterey<12.0.1
12.0.1
Apple iOS<14.8.1
14.8.1
Apple iPadOS<14.8.1
14.8.1
Apple iOS<15.1
15.1
Apple iPadOS<15.1
15.1
Apple Ipad Os<14.8.1
Apple iPadOS=15.0
Apple iPhone OS<14.8.1
Apple iPhone OS=15.0
Apple iOS and macOS<10.15.7
Apple iOS and macOS=10.15.7
Apple iOS and macOS=10.15.7-security_update_2020-001
Apple iOS and macOS=10.15.7-security_update_2021-001
Apple iOS and macOS=10.15.7-security_update_2021-002
Apple iOS and macOS=10.15.7-security_update_2021-003
Apple iOS and macOS=10.15.7-security_update_2021-004
Apple iOS and macOS=10.15.7-security_update_2021-005
Apple iOS and macOS=10.15.7-security_update_2021-006
Apple iOS and macOS=10.15.7-supplemental_update
Apple macOS>=11.0<11.6.1
Apple macOS=12.0
Apple tvOS<15.1
Apple WatchOS<8.1
Event History
Aug 24, 2021
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-30917?
CVE-2021-30917 is a memory corruption issue in the processing of ICC profiles in ColorSync.
2
Who is affected by CVE-2021-30917?
Users of Apple products such as Catalina, macOS Big Sur, macOS Monterey, iOS, iPadOS, watchOS, and tvOS are affected.
3
How can I fix CVE-2021-30917?
Apply the recommended remedies provided by Apple for your specific product version as mentioned in the references.
4
What is the severity of CVE-2021-30917?
The severity of CVE-2021-30917 is not mentioned in the provided information.
5
Where can I find more information about CVE-2021-30917?
You can find more information about CVE-2021-30917 on the official Apple support website mentioned in the references.