CVE-2021-30939: Apple macOS ImageIO DDS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
Other sources
ImageIO. An out-of-bounds read was addressed with improved bounds checking.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the ImageIO framework. Crafted data in a DDS image can trigger a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30950
- CVE-2021-30931
- CVE-2021-30935
- CVE-2021-30942
- CVE-2021-30957
- CVE-2021-30962
- CVE-2021-30959
- CVE-2021-30961
- CVE-2021-30963
- CVE-2021-30958
- CVE-2021-30945
- CVE-2021-31007
- CVE-2021-31013
- CVE-2021-30895
- CVE-2021-30977
- CVE-2021-30969
- CVE-2021-30939
- CVE-2021-30981
- CVE-2021-30982
- CVE-2021-30927
- CVE-2021-30980
- CVE-2021-30937
- CVE-2021-30949
- CVE-2021-30990
- CVE-2021-30976
- CVE-2021-30929
- CVE-2021-30979
- CVE-2021-30940
- CVE-2021-30941
- CVE-2021-30973
- CVE-2021-30971
- CVE-2021-30995
- CVE-2021-30968
- CVE-2021-30947
- CVE-2021-30946
- CVE-2021-30975
- CVE-2021-31002
- CVE-2021-30767
- CVE-2021-30970
- CVE-2021-30965
- CVE-2021-30938
- CVE-2021-30960
- CVE-2021-30966
- CVE-2021-30926
- CVE-2021-31000
- CVE-2021-30916
- CVE-2021-30993
- CVE-2021-30955
- CVE-2021-30944
- CVE-2021-30934
- CVE-2021-30936
- CVE-2021-30951
- CVE-2021-30952
- CVE-2021-30984
- CVE-2021-30953
- CVE-2021-30954
- CVE-2021-30943
- CVE-2021-30964
- CVE-2021-30987
- CVE-2021-30986
- CVE-2021-30996
- CVE-2021-31009
- CVE-2021-30972
- CVE-2021-30956
- CVE-2021-30992
- CVE-2021-30983
- CVE-2021-30985
- CVE-2021-30991
- CVE-2021-30998
- CVE-2021-30997
- CVE-2021-30967
- CVE-2021-30988
- CVE-2021-30932
- CVE-2021-30948
Frequently Asked Questions
What is CVE-2021-30939?
CVE-2021-30939 is a vulnerability in Apple macOS that allows remote attackers to disclose sensitive information.
How severe is CVE-2021-30939?
CVE-2021-30939 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2021-30939?
CVE-2021-30939 affects Apple macOS Monterey 12.1, tvOS 15.2, watchOS 8.3, macOS Big Sur 11.6.2, iOS 15.2, and iPadOS 15.2.
How can CVE-2021-30939 be exploited?
Exploiting CVE-2021-30939 requires interaction with the ImageIO library, and the attack vectors may vary depending on the implementation.
Are there any remediation steps available for CVE-2021-30939?
Yes, Apple has released security updates to address CVE-2021-30939. Please refer to the official Apple advisory for more information.