VDB
CVE-2021-1778
CVE-2021-1778
PUBLISHED
CVSS 4.300000190734863 MEDIUM
An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
EPSS 0.31% · 54.3th percentile
Risk Scores
CVSS v2.0
4.300000190734863
EPSS Score
0.31%
54.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | |
| Apple | macOS | |
| n/a | n/a | n/a |
| apple | watchos | 0, 0, 0 |
| apple | mac_os_x | 10.14, 10.14.6, 10.14.6 |
| apple | macos | 11.0, 11.0, 11.0 |
| apple | iphone_os | 0, 0, 0 |
| apple | ipados | 0, 0, 0 |
| apple | tvos | 0, 0, 0 |
Timeline
- Apr 2, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 27, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://support.apple.com/fr-fr/HT212152 advisory
- https://support.apple.com/fr-fr/HT212147 advisory
- https://bugs.gentoo.org/717920 url
- https://www.pcre.org/original/changelog.txt url
- https://support.apple.com/kb/HT211931 url
- 20201215 APPLE-SA-2020-12-14-4 Additional information for APPLE-SA-2020-11-13-1 macOS Big Sur 11.0.1 mailing-list
- https://support.apple.com/kb/HT212147 url
- 20210201 APPLE-SA-2021-02-01-1 macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave mailing-list
- [mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2021-1778 advisory
- https://support.apple.com/en-us/HT212146 url
- https://support.apple.com/en-us/HT212147 url
- https://support.apple.com/en-us/HT212148 url
- https://support.apple.com/en-us/HT212149 url