Analysis of iOS & OS X Vulnerability: CVE-2016-1722
ID: 77220851-786d-56f5-8f65-b611e145ecdf
STIX ID: report--77220851-786d-56f5-8f65-b611e145ecdf
Feed Name: Zimperium Blog
Threat Score
This advisory describes a heap-buffer overflow in syslogd (dbserver.c add_lockdown_session) caused by a mistaken size calculation in reallocf that leads to out-of-bounds writes of file-descriptor values; it affects iOS 6.0–9.2 and OS X 10.9–10.11.2, can cause crashes and under certain scenarios enable local privilege escalation or remote code execution from a trusted/paired host, and was reported to and patched by Apple in the iOS 9.2.1 update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
