CVE-2022-32886
Description
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
CWE
- CWE-787 — CWE-787 Out-of-bounds Write
Affected
- Apple / iOS — v=unspecified <16 [affected]
- Apple / Safari — v=unspecified <16 [affected]
- Apple / iOS and iPadOS — v=unspecified <15.7 [affected]
CVSS
- (none)
References
- https://support.apple.com/en-us/HT213446
- https://support.apple.com/en-us/HT213445
- https://support.apple.com/en-us/HT213442
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDV6OLKDTL55NH4LNSMLQ4D6LLSX6JU2/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/74MXH2U5GA4CX3L3NLYP4TBO4O2VOPBJ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDNT32WIARRD2ANWKGCTTIQXI6OII7HZ/ vendor-advisory
- https://www.debian.org/security/2022/dsa-5240 vendor-advisory
- https://www.debian.org/security/2022/dsa-5241 vendor-advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00034.html mailing-list
- http://seclists.org/fulldisclosure/2022/Oct/41 mailing-list
- http://seclists.org/fulldisclosure/2022/Oct/28 mailing-list
- http://seclists.org/fulldisclosure/2022/Oct/39 mailing-list
- https://security.gentoo.org/glsa/202305-32
Source
cvelistV5-main/cves/2022/32xxx/CVE-2022-32886.json