CVE-2024-40806

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing a maliciously crafted file may lead to unexpected app termination.
References
Link Resource
http://seclists.org/fulldisclosure/2024/Jul/16 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/17 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/18 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/19 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/20 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/21 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/22 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/23 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214116 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214117 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214118 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214119 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214120 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214122 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214123 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214124 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

15 Aug 2024, 16:42

Type Values Removed Values Added
CPE cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () http://seclists.org/fulldisclosure/2024/Jul/16 - () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/17 - () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/18 - () http://seclists.org/fulldisclosure/2024/Jul/18 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/19 - () http://seclists.org/fulldisclosure/2024/Jul/19 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/20 - () http://seclists.org/fulldisclosure/2024/Jul/20 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/21 - () http://seclists.org/fulldisclosure/2024/Jul/21 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/22 - () http://seclists.org/fulldisclosure/2024/Jul/22 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/23 - () http://seclists.org/fulldisclosure/2024/Jul/23 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214116 - () https://support.apple.com/en-us/HT214116 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214117 - () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214118 - () https://support.apple.com/en-us/HT214118 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214119 - () https://support.apple.com/en-us/HT214119 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214120 - () https://support.apple.com/en-us/HT214120 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214122 - () https://support.apple.com/en-us/HT214122 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214123 - () https://support.apple.com/en-us/HT214123 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214124 - () https://support.apple.com/en-us/HT214124 - Release Notes, Vendor Advisory
First Time Apple macos
Apple watchos
Apple iphone Os
Apple tvos
Apple
Apple ipados
Apple visionos
CWE CWE-125

30 Jul 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de lectura fuera de los límites con una validación de entrada mejorada. Este problema se solucionó en iOS 16.7.9 y iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 y iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Procesar un archivo creado con fines malintencionados puede provocar la finalización inesperada de la aplicación.

30 Jul 2024, 02:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/18 -
  • () http://seclists.org/fulldisclosure/2024/Jul/19 -

30 Jul 2024, 01:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/16 -
  • () http://seclists.org/fulldisclosure/2024/Jul/17 -
  • () http://seclists.org/fulldisclosure/2024/Jul/20 -
  • () http://seclists.org/fulldisclosure/2024/Jul/21 -
  • () http://seclists.org/fulldisclosure/2024/Jul/22 -
  • () http://seclists.org/fulldisclosure/2024/Jul/23 -

29 Jul 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 23:15

Updated : 2024-08-15 16:42


NVD link : CVE-2024-40806

Mitre link : CVE-2024-40806

CVE.ORG link : CVE-2024-40806


JSON object : View

Products Affected

apple

  • ipados
  • watchos
  • tvos
  • iphone_os
  • macos
  • visionos
CWE
CWE-125

Out-of-bounds Read