Vulnerability CVE-2016-7592: Information

Description

An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.

Severity: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Published: Feb. 20, 2017
Modified: July 27, 2017
Error type identifier: CWE-200

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libwebkitgtk4sisyphus2.14.3-alt12.44.1-alt1ALT-PU-2017-1049-1176784Fixed
libwebkitgtk4p102.14.3-alt12.36.3-alt1ALT-PU-2017-1049-1176784Fixed
libwebkitgtk4p92.14.3-alt12.24.4-alt1.3.p9ALT-PU-2017-1049-1176784Fixed
libwebkitgtk4p82.14.4-alt0.M80P.12.20.2-alt0.M80P.1ALT-PU-2017-1162-1178042Fixed
libwebkitgtk4c10f12.14.3-alt12.36.3-alt1ALT-PU-2017-1049-1176784Fixed
libwebkitgtk4c9f22.14.3-alt12.24.4-alt1.3.c9.1ALT-PU-2017-1049-1176784Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
      End including
      10.1.1

      Configuration 2

      cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
      End including
      10.0.1

      Configuration 3

      cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:*
      End including
      6.0.1

      Configuration 4

      cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*
      End including
      12.5.3