Vulnerabilities > CVE-2016-1821 - Unspecified vulnerability in Apple mac OS X
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
Vulnerable Configurations
Exploit-Db
description | OS X Kernel - Exploitable NULL Pointer Dereference in IOAudioEngine. CVE-2016-1821. Dos exploit for osx platform |
file | exploits/osx/dos/39926.c |
id | EDB-ID:39926 |
last seen | 2016-06-11 |
modified | 2016-06-10 |
platform | osx |
port | |
published | 2016-06-10 |
reporter | Google Security Research |
source | https://www.exploit-db.com/download/39926/ |
title | OS X Kernel - Exploitable NULL Pointer Dereference in IOAudioEngine |
type | dos |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_10_11_5.NASL |
description | The remote host is running a version of Mac OS X that is 10.11.x prior to 10.11.5. It is, therefore, affected by multiple vulnerabilities in the following components : - AMD - apache_mod_php - AppleGraphicsControl - AppleGraphicsPowerManagement - Assistant - ATS - Audio - Captive - CFNetwork - CommonCrypto - CoreCapture - CoreStorage - Crash - Disk - Disk - Driver - Drivers - Drivers - Graphics - Graphics - Graphics - ImageIO - Images - Intel - IOAcceleratorFamily - IOAudioFamily - IOFireWireFamily - IOHIDFamily - Kernel - libc - libxml2 - libxslt - Lock - MapKit - Messages - Multi-Touch - Network - NVIDIA - OpenGL - Proxies - QuickTime - Reporter - SceneKit - Screen - Tcl - Utility Note that successful exploitation of the most serious issues can result in arbitrary code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 91228 |
published | 2016-05-19 |
reporter | This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/91228 |
title | Mac OS X 10.11.x < 10.11.5 Multiple Vulnerabilities |
code |
|
References
- http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
- http://lists.apple.com/archives/security-announce/2016/May/msg00004.html
- http://www.securityfocus.com/bid/90696
- http://www.securityfocus.com/bid/90696
- http://www.securitytracker.com/id/1035895
- http://www.securitytracker.com/id/1035895
- https://bugs.chromium.org/p/project-zero/issues/detail?id=776
- https://bugs.chromium.org/p/project-zero/issues/detail?id=776
- https://support.apple.com/HT206567
- https://support.apple.com/HT206567
- https://www.exploit-db.com/exploits/39926/
- https://www.exploit-db.com/exploits/39926/