CVE-2023-42926

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References
Link Resource
http://packetstormsecurity.com/files/176535/macOS-AppleGVA-Memory-Handling.html Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2023/Dec/9 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214036 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Feb 2024, 03:11

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/176535/macOS-AppleGVA-Memory-Handling.html - () http://packetstormsecurity.com/files/176535/macOS-AppleGVA-Memory-Handling.html - Third Party Advisory, VDB Entry

12 Jan 2024, 16:15

Type Values Removed Values Added
References
  • () http://packetstormsecurity.com/files/176535/macOS-AppleGVA-Memory-Handling.html -

13 Dec 2023, 21:16

Type Values Removed Values Added
CWE CWE-787
First Time Apple
Apple macos
References () http://seclists.org/fulldisclosure/2023/Dec/9 - () http://seclists.org/fulldisclosure/2023/Dec/9 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214036 - () https://support.apple.com/en-us/HT214036 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

13 Dec 2023, 01:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2023/Dec/9 -

12 Dec 2023, 13:43

Type Values Removed Values Added
Summary
  • (es) Se abordaron múltiples problemas de corrupción de memoria con una validación de entrada mejorada. Este problema se solucionó en macOS Sonoma 14.2. El procesamiento de un archivo creado con fines malintencionados puede provocar la finalización inesperada de la aplicación o la ejecución de código arbitrario.

12 Dec 2023, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-12 01:15

Updated : 2024-02-02 03:11


NVD link : CVE-2023-42926

Mitre link : CVE-2023-42926

CVE.ORG link : CVE-2023-42926


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-787

Out-of-bounds Write