2023-09-27 16:00:29 +00:00
{
"id" : "CVE-2023-40436" ,
"sourceIdentifier" : "product-security@apple.com" ,
"published" : "2023-09-27T15:19:15.910" ,
2023-10-12 04:00:29 +00:00
"lastModified" : "2023-10-12T02:26:39.720" ,
"vulnStatus" : "Analyzed" ,
2023-09-27 16:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to cause unexpected system termination or read kernel memory."
2023-10-03 08:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "El problema se solucion\u00f3 con comprobaciones de los l\u00edmites mejoradas. Este problema se solucion\u00f3 en macOS Sonoma 14. Un atacante puede provocar la terminaci\u00f3n inesperada del sistema o leer la memoria del kernel."
2023-09-27 16:00:29 +00:00
}
] ,
2023-09-27 20:00:29 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.1 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.2
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "14.0" ,
"matchCriteriaId" : "7A5DD3D5-FB4F-4313-B873-DCED87FC4605"
}
]
}
]
}
] ,
2023-09-27 16:00:29 +00:00
"references" : [
2023-10-03 08:00:28 +00:00
{
"url" : "http://seclists.org/fulldisclosure/2023/Oct/3" ,
2023-10-12 04:00:29 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
2023-10-03 08:00:28 +00:00
} ,
2023-09-27 16:00:29 +00:00
{
"url" : "https://support.apple.com/en-us/HT213940" ,
2023-09-27 20:00:29 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
2023-09-27 16:00:29 +00:00
}
]
}