Array Overflow Vulnerability in IOAcceleratorFamily2 Module (CVE-2016-1718)
Data de publicação: 05 abril 2016
Schweregrad: : Medium
Identificador(es) CVE: : CVE-2016-1718
Data do informe: 19 janeiro 2016
Descrição
This vulnerability affects OS X below 10.11.3. It occurs by sending two special requests to IOAcceleratorFamily2 module. As such, an array overflow happens in method IOAccelDispalyMachine2::getFramebufferCount. This may lead to local privilege escalation. While this vulnerability is not easy to exploit, we advise users to upgrade their OS X to the latest version.
Trend Micro researcher Juwei Lin disclosed details about this vulnerability to Apple.