logo

Analysis of iOS & OS X Vulnerability: CVE-2016-1722

ID: 77220851-786d-56f5-8f65-b611e145ecdf

STIX ID: report--77220851-786d-56f5-8f65-b611e145ecdf

Feed Name: Zimperium Blog

Threat Score
55/100

Date Published: 2016-01-23

Date Updated: 2026-05-01

...
...

This advisory describes a heap-buffer overflow in syslogd (dbserver.c add_lockdown_session) caused by a mistaken size calculation in reallocf that leads to out-of-bounds writes of file-descriptor values; it affects iOS 6.0–9.2 and OS X 10.9–10.11.2, can cause crashes and under certain scenarios enable local privilege escalation or remote code execution from a trusted/paired host, and was reported to and patched by Apple in the iOS 9.2.1 update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.