iOS/macOS Remote code execution... CVE-2017-2416 CNNVD-201704-061

6.8 AV AC AU C I A
发布: 2017-04-02
修订: 2019-03-08

> ImageIO Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later > > Impact: Processing a maliciously crafted image may lead to arbitrary code execution > > Description: A memory corruption issue was addressed through improved input validation. > > CVE-2017-2416: flanker_hqd of KeenLab, Tencent ### Abstract Recently I’ve switched my main research focus back from Apple stuff to Android and browsers. While I was auditing a custom image parsing library written by some ppls, I transferred the test case image manipulated by 010editor via a popular IM messenger, and all of a sudden, the app crashed. I investigated the crash and found it is a issue in ImageIO library, and can be automatically triggered in all kinds of iOS/macOS apps that receives GIF images, especially the ones for instant messaging, such as `Signal, Telegram, Slack, iMessage` etc and Email clients such as `Mail, Outlook, Inbox, Gmail`, etc and even financial apps that want...

0%
暂无可用Exp或PoC
当前有4条受影响产品信息