{"id":59980,"date":"2024-10-30T01:29:28","date_gmt":"2024-10-29T22:29:28","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182366\/APPLE-SA-10-28-2024-7.txt"},"modified":"2024-10-30T01:29:28","modified_gmt":"2024-10-29T22:29:28","slug":"apple-security-advisory-10-28-2024-7","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-10-28-2024-7\/","title":{"rendered":"Apple Security Advisory 10-28-2024-7"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-10-28-2024-7 tvOS 18.1<\/p>\n<p>tvOS 18.1 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121569.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>App Support<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: A malicious app may be able to run arbitrary shortcuts without<br \/>user consent<br \/>Description: A path handling issue was addressed with improved logic.<br \/>CVE-2024-44255: an anonymous researcher<\/p>\n<p>CoreMedia Playback<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: A malicious app may be able to access private information<br \/>Description: This issue was addressed with improved handling of<br \/>symlinks.<br \/>CVE-2024-44273: pattern-f (@pattern_F_), Hikerell of Loadshine Lab<\/p>\n<p>CoreText<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Processing a maliciously crafted font may result in the<br \/>disclosure of process memory<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44240: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44302: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Foundation<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44282: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>ImageIO<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Processing an image may result in disclosure of process memory<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44215: Junsung Lee working with Trend Micro Zero Day Initiative<\/p>\n<p>ImageIO<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Processing a maliciously crafted message may lead to a denial-<br \/>of-service<br \/>Description: The issue was addressed with improved bounds checks.<br \/>CVE-2024-44297: Jex Amro<\/p>\n<p>IOSurface<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An app may be able to cause unexpected system termination or<br \/>corrupt kernel memory<br \/>Description: A use-after-free issue was addressed with improved memory<br \/>management.<br \/>CVE-2024-44285: an anonymous researcher<\/p>\n<p>Kernel<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An app may be able to leak sensitive kernel state<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44239: Mateusz Krzywicki (@krzywix)<\/p>\n<p>Managed Configuration<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Restoring a maliciously crafted backup file may lead to<br \/>modification of protected system files<br \/>Description: This issue was addressed with improved handling of<br \/>symlinks.<br \/>CVE-2024-44258: Hichem Maloufi, Christian Mina, Ismail Amzdak<\/p>\n<p>MobileBackup<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Restoring a maliciously crafted backup file may lead to<br \/>modification of protected system files<br \/>Description: A logic issue was addressed with improved file handling.<br \/>CVE-2024-44252: Nimrat Khalsa, Davis Dai, James Gill<br \/>(@jjtech@infosec.exchange)<\/p>\n<p>Pro Res<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An app may be able to cause unexpected system termination or<br \/>corrupt kernel memory<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-44277: an anonymous researcher and Yinyi Wu(@_3ndy1) from Dawn<br \/>Security Lab of JD.com, Inc.<\/p>\n<p>WebKit<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Processing maliciously crafted web content may prevent Content<br \/>Security Policy from being enforced<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 278765<br \/>CVE-2024-44296: Narendra Bhati, Manager of Cyber Security at Suma Soft<br \/>Pvt. Ltd, Pune (India)<\/p>\n<p>WebKit<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: A memory corruption issue was addressed with improved input<br \/>validation.<br \/>WebKit Bugzilla: 279780<br \/>CVE-2024-44244: an anonymous researcher, Q1IQ (@q1iqF) and P1umer<br \/>(@p1umer)<\/p>\n<p>Additional recognition<\/p>\n<p>ImageIO<br \/>We would like to acknowledge Amir Bazine and Karsten K\u00f6nig of<br \/>CrowdStrike Counter Adversary Operations, an anonymous researcher for<br \/>their assistance.<\/p>\n<p>NetworkExtension<br \/>We would like to acknowledge Patrick Wardle of DoubleYou &amp; the<br \/>Objective-See Foundation for their assistance.<\/p>\n<p>Photos<br \/>We would like to acknowledge James Robertson for their assistance.<\/p>\n<p>Security<br \/>We would like to acknowledge Bing Shi, Wenchao Li and Xiaolong Bai of<br \/>Alibaba Group for their assistance.<\/p>\n<p>Apple TV will periodically check for software updates. Alternatively,<br \/>you may manually check for software updates by selecting<br \/>&#8220;Settings -&gt; System -&gt; Software Update -&gt; Update Software.&#8221;<\/p>\n<p>To check the current version of software, select<br \/>&#8220;Settings -&gt; General \u2192 About.\u201c<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmcgAScACgkQX+5d1TXa<br \/>IvpzYBAAoCN0SuujtunAgU1eUmXrdnRze4Jf5Wwz23Qra51OgKehUlK2n1DuToJM<br \/>Gs3Bw6inMGX+kizS4vhInhoJ7Z4kArROvKooV6qBtJw5lq7Imxr3E7305dWU230s<br \/>HRjaMamEE3llDflvOo5fiKiKBYihuH+qOZ\/jrdzdPSaw4zpw5gDA6za5pfAnW58U<br \/>2tzwM0zSkAXiAIBrzYlNVcmL7EYdLgullxsSK6KI26qWRAWsN9u5PljzfCBOr1vo<br \/>5geJY3EFSjdcrWm1s3AKYCPJQgiL3UwcGFIQqyKsrtwRaFUuM0l\/nOIdvP8SW2BY<br \/>8wC06REVN2yV29qECsBhtaqXwybBDdwZiBaJ7BaAnHTZzrd0Vc00LC2UgMhT+Qb8<br \/>9EtcgsrImVqVKFXsdYvQlqxuWGYJRjkpMuWF2aCtqgjPvUfipzB0HDMhqgFpzeet<br \/>EIMFYEV+IqoNYg6AfrsBA+ok4IHaVSyTWHB0k5rQM0YVaVF6MHqZYhKj\/lbiHax9<br \/>sJbEaDkiFF+xHSKc3LnoG+KTlXboHaaNDyD4\/uyEsrcS1S9y4Ni+WnZi2ufluItW<br \/>Wl7aRYr+UMR6qc7zWL2mY5cafT\/hfNVu6tUbfIWyN5LE9imT27IIVZfzsQ299PCF<br \/>Kmi61d0fwS9AuJrxic1TnMbNEGS2g0NLcmTEMeIWFatzhpurglA=<br \/>=zC9Y<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-10-28-2024-7 tvOS 18.1 tvOS 18.1 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121569. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. App SupportAvailable for: Apple TV HD and Apple TV 4K (all models)Impact: A malicious app may be able to &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59980","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59980"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59980\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}