CVE-2023-38611: Buffer Overflow
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppSandbox. A logic issue was addressed with improved restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-36495
- CVE-2023-38604
- CVE-2023-32734
- CVE-2023-32441
- CVE-2023-38606
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38593
- CVE-2023-38565
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38572
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38133
- CVE-2023-34425
- CVE-2023-38136
- CVE-2023-38580
- CVE-2023-32416
- CVE-2023-40439
- CVE-2023-38616
- CVE-2023-36862
- CVE-2023-32364
- CVE-2023-35983
- CVE-2023-40392
- CVE-2023-42828
- CVE-2023-34241
- CVE-2023-28319
- CVE-2023-28320
- CVE-2023-28321
- CVE-2023-28322
- CVE-2023-40437
- CVE-2023-32418
- CVE-2023-36854
- CVE-2022-3970
- CVE-2023-28200
- CVE-2023-37285
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38410
- CVE-2023-38603
- CVE-2023-40440
- CVE-2023-38258
- CVE-2023-38421
- CVE-2023-1916
- CVE-2023-38571
- CVE-2023-29491
- CVE-2023-38601
- CVE-2023-32444
- CVE-2023-2953
- CVE-2023-42829
- CVE-2023-38609
- CVE-2023-38259
- CVE-2023-38564
- CVE-2023-38602
- CVE-2023-42831
- CVE-2023-32442
- CVE-2023-32443
- CVE-2023-42832
- CVE-2023-32429
- CVE-2023-1801
- CVE-2023-32654
- CVE-2023-2426
- CVE-2023-2609
- CVE-2023-2610
- CVE-2023-38608
- CVE-2023-38605
- CVE-2023-40397
- CVE-2023-38597
- CVE-2023-40442
- CVE-2023-41995
- CVE-2023-40400
- CVE-2023-40394
- CVE-2023-32437
- CVE-2023-43000
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38611.
What is the severity level of CVE-2023-38611?
CVE-2023-38611 has a severity level of high.
Which software versions are affected by CVE-2023-38611?
CVE-2023-38611 affects Apple tvOS up to and excluding version 16.6, Apple iOS up to and excluding version 16.6, Apple iPadOS up to and excluding version 16.6, Apple watchOS up to and excluding version 9.6, Apple Safari up to and excluding version 16.6, Apple macOS Ventura up to and excluding version 13.5, Ubuntu webkit2gtk up to and excluding version 2.40.5, Ubuntu webkit2gtk-jammy up to and excluding version 2.40.5-0ubuntu0.23.04.1, and Ubuntu webkit2gtk-lunar up to and excluding version 2.40.5-0ubuntu0.22.04.1.
How can I fix CVE-2023-38611?
To fix CVE-2023-38611, update your software to the following versions: Apple tvOS 16.6, Apple iOS 16.6, Apple iPadOS 16.6, Apple watchOS 9.6, Apple Safari 16.6, Apple macOS Ventura 13.5, Ubuntu webkit2gtk 2.40.5, Ubuntu webkit2gtk-jammy 2.40.5-0ubuntu0.23.04.1, and Ubuntu webkit2gtk-lunar 2.40.5-0ubuntu0.22.04.1.
Can processing web content lead to arbitrary code execution for CVE-2023-38611?
Yes, processing web content may lead to arbitrary code execution for CVE-2023-38611.