CVE-2017-6975

Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom firmware functions, there is a separate CVE ID for the operating-system behavior.
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:30

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2019/May/24 - () http://seclists.org/fulldisclosure/2019/May/24 -
References () http://www.securityfocus.com/bid/97328 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/97328 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1038172 - () http://www.securitytracker.com/id/1038172 -
References () https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html - Exploit, Technical Description, Third Party Advisory () https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html - Exploit, Technical Description, Third Party Advisory
References () https://seclists.org/bugtraq/2019/May/30 - () https://seclists.org/bugtraq/2019/May/30 -
References () https://support.apple.com/HT207688 - Vendor Advisory () https://support.apple.com/HT207688 - Vendor Advisory
References () https://support.apple.com/kb/HT210121 - () https://support.apple.com/kb/HT210121 -
References () https://twitter.com/4Dgifts/status/849268365457850370 - Third Party Advisory () https://twitter.com/4Dgifts/status/849268365457850370 - Third Party Advisory

Information

Published : 2017-04-05 14:59

Updated : 2024-11-21 03:30


NVD link : CVE-2017-6975

Mitre link : CVE-2017-6975

CVE.ORG link : CVE-2017-6975


JSON object : View

Products Affected

apple

  • iphone_os
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer