ID

VAR-202201-0423


CVE

CVE-2022-22579


TITLE

plural  Apple  Vulnerability related to resource disclosure to the wrong area in the product

Trust: 0.8

sources: JVNDB: JVNDB-2022-008988

DESCRIPTION

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution. plural Apple The product contains a resource disclosure vulnerability to the wrong area.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the ModelIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.The specific flaw exists within the ModelIO framework. Crafted data in an STL file can trigger a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. CVE-2022-22591: Antonio Zekic (@antoniozekic) of Diverto IOMobileFrameBuffer Available for: macOS Monterey Impact: A malicious application may be able to execute arbitrary code with kernel privileges. PackageKit We would like to acknowledge Mickey Jin (@patch1t), Mickey Jin (@patch1t) of Trend Micro for their assistance. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2022-01-26-1 iOS 15.3 and iPadOS 15.3 iOS 15.3 and iPadOS 15.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213053. ColorSync Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: Processing a maliciously crafted file may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved validation. CVE-2022-22584: Mickey Jin (@patch1t) of Trend Micro Crash Reporter Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A malicious application may be able to gain root privileges Description: A logic issue was addressed with improved validation. CVE-2022-22578: an anonymous researcher iCloud Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: An application may be able to access a user's files Description: An issue existed within the path validation logic for symlinks. CVE-2022-22585: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab (https://xlab.tencent.com) IOMobileFrameBuffer Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. CVE-2022-22587: an anonymous researcher, Meysam Firouzi (@R00tkitSMM) of MBition - Mercedes-Benz Innovation Lab, Siddharth Aeri (@b1n4r1b01) Kernel Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A malicious application may be able to execute arbitrary code with kernel privileges Description: A buffer overflow issue was addressed with improved memory handling. CVE-2022-22593: Peter Nguyễn Vũ Hoàng of STAR Labs Model I/O Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution Description: An information disclosure issue was addressed with improved state management. CVE-2022-22579: Mickey Jin (@patch1t) of Trend Micro WebKit Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript Description: A validation issue was addressed with improved input sanitization. CVE-2022-22589: Heige of KnownSec 404 Team (knownsec.com) and Bo Qu of Palo Alto Networks (paloaltonetworks.com) WebKit Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management. CVE-2022-22590: Toan Pham from Team Orca of Sea Security (security.sea.com) WebKit Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced Description: A logic issue was addressed with improved state management. CVE-2022-22592: Prakash (@1lastBr3ath) WebKit Storage Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A website may be able to track sensitive user information Description: A cross-origin issue in the IndexDB API was addressed with improved input validation. CVE-2022-22594: Martin Bajanik of FingerprintJS Additional recognition WebKit We would like to acknowledge Prakash (@1lastBr3ath) for their assistance. Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About * The version after applying this update will be “15.3" Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEePiLW1MrMjw19XzoeC9qKD1prhgFAmHx0vIACgkQeC9qKD1p rhj4hBAAuITBqrZx38zr9+MFgchRltErtLD/ZVUZ0mYD/bbVaF8+2RwoP0d3XBHj hkiZAqV8LCe+r9qs2SHBxXZteEEs79R1AIzZCSAjMU9LUK8yXYgHC5BGDoanRmes yuFyrWp78zz5Ix3jop5SUTt0xcxSOK49m7Oozrgr4sfzDg83VzDF9ebna+Obcar1 WArT/yhPC35dwJ5tOJ0Xmdogb3gPEk+ccjw885UpjnQqnkX8g0KOUzRSp/BYwexM vea9a7z3IGrCHaU8rlJWX+GupMUgRtpZr/k6jCzwT7g4BDRYSMYFvJcKZF6xFNgy raxl8Vdm+ZhTK//YNFl7BB1aKixVzI6i85aegtOErUPRwzICD1NDlQK5q3ErBpp+ 5FTvuwn7SWy5BPkSIOwmfoJfGrWTzDmdOAajM5o6Yy5m/OnR5ZqK4egfvwmPjoEy lx9ffhcvm7HbQmLjO4DTQlpqiyk3UmMmE5MEG4QSMA5UOqMinjE0kl+2JEkV7cmt Ugkcc4Auu7jUM3YxCkPfMi/x4/t52BBJbIXzpLnj2qebpci7GW9c3aDPNoQbTty9 +Y1amSmQvVRlqKGEi2xlVKGqN0uduhanyiL6+tt2Q1Afo/jf6JjERVUrOGl/Fv7r sJKt1GE0w3uJ6RQVQ6C3w33HTmzNWwzfdy+I8Ik3Cn8ZgfHY3JA= =JRMz -----END PGP SIGNATURE-----

Trust: 2.88

sources: NVD: CVE-2022-22579 // JVNDB: JVNDB-2022-008988 // ZDI: ZDI-22-361 // VULHUB: VHN-411207 // VULMON: CVE-2022-22579 // PACKETSTORM: 165775 // PACKETSTORM: 165774 // PACKETSTORM: 165773 // PACKETSTORM: 165772 // PACKETSTORM: 165771

AFFECTED PRODUCTS

vendor:applemodel:ipadosscope:ltversion:15.3

Trust: 1.0

vendor:applemodel:macosscope:gteversion:12.0.0

Trust: 1.0

vendor:applemodel:tvosscope:ltversion:15.3

Trust: 1.0

vendor:applemodel:macosscope:ltversion:11.6.3

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.15.7

Trust: 1.0

vendor:applemodel:macosscope:ltversion:12.2

Trust: 1.0

vendor:applemodel:iphone osscope:ltversion:15.3

Trust: 1.0

vendor:applemodel:mac os xscope:ltversion:10.15.7

Trust: 1.0

vendor:アップルmodel:ipadosscope: - version: -

Trust: 0.8

vendor:アップルmodel:tvosscope: - version: -

Trust: 0.8

vendor:アップルmodel:macosscope: - version: -

Trust: 0.8

vendor:アップルmodel:apple mac os xscope: - version: -

Trust: 0.8

vendor:アップルmodel:iosscope: - version: -

Trust: 0.8

vendor:applemodel:macosscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-22-361 // JVNDB: JVNDB-2022-008988 // NVD: CVE-2022-22579

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-22579
value: HIGH

Trust: 1.0

NVD: CVE-2022-22579
value: HIGH

Trust: 0.8

ZDI: CVE-2022-22579
value: LOW

Trust: 0.7

CNNVD: CNNVD-202201-2416
value: HIGH

Trust: 0.6

VULHUB: VHN-411207
value: HIGH

Trust: 0.1

VULMON: CVE-2022-22579
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2022-22579
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-411207
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2022-22579
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-22579
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

ZDI: CVE-2022-22579
baseSeverity: LOW
baseScore: 3.3
vectorString: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 1.4
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-22-361 // VULHUB: VHN-411207 // VULMON: CVE-2022-22579 // JVNDB: JVNDB-2022-008988 // CNNVD: CNNVD-202201-2416 // NVD: CVE-2022-22579

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Leakage of resources to the wrong area (CWE-668) [NVD evaluation ]

Trust: 0.8

problemtype:CWE-668

Trust: 0.1

sources: VULHUB: VHN-411207 // JVNDB: JVNDB-2022-008988 // NVD: CVE-2022-22579

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202201-2416

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202201-2416

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-411207

PATCH

title:HT213057url:https://support.apple.com/en-us/HT213053

Trust: 0.8

title:Apple has issued an update to correct this vulnerability.url:https://support.apple.com/HT213055

Trust: 0.7

title:Apple macOS Buffer error vulnerability fixurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=182350

Trust: 0.6

title:Apple: iOS 15.3 and iPadOS 15.3url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=05e71c916b30e0c013cc3ece80cc9189

Trust: 0.1

title:CVE-2022-XXXXurl:https://github.com/AlphabugX/CVE-2022-23305

Trust: 0.1

title:CVE-2022-XXXXurl:https://github.com/AlphabugX/CVE-2022-RCE

Trust: 0.1

sources: ZDI: ZDI-22-361 // VULMON: CVE-2022-22579 // JVNDB: JVNDB-2022-008988 // CNNVD: CNNVD-202201-2416

EXTERNAL IDS

db:NVDid:CVE-2022-22579

Trust: 4.6

db:ZDIid:ZDI-22-361

Trust: 1.4

db:PACKETSTORMid:165774

Trust: 0.8

db:PACKETSTORMid:165775

Trust: 0.8

db:JVNDBid:JVNDB-2022-008988

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-15639

Trust: 0.7

db:CS-HELPid:SB2022012636

Trust: 0.6

db:AUSCERTid:ESB-2022.0408

Trust: 0.6

db:AUSCERTid:ESB-2022.0406

Trust: 0.6

db:CNNVDid:CNNVD-202201-2416

Trust: 0.6

db:PACKETSTORMid:165772

Trust: 0.2

db:PACKETSTORMid:165771

Trust: 0.2

db:PACKETSTORMid:165773

Trust: 0.2

db:VULHUBid:VHN-411207

Trust: 0.1

db:VULMONid:CVE-2022-22579

Trust: 0.1

sources: ZDI: ZDI-22-361 // VULHUB: VHN-411207 // VULMON: CVE-2022-22579 // JVNDB: JVNDB-2022-008988 // PACKETSTORM: 165775 // PACKETSTORM: 165774 // PACKETSTORM: 165773 // PACKETSTORM: 165772 // PACKETSTORM: 165771 // CNNVD: CNNVD-202201-2416 // NVD: CVE-2022-22579

REFERENCES

url:https://support.apple.com/en-us/ht213054

Trust: 2.4

url:https://support.apple.com/en-us/ht213053

Trust: 1.8

url:https://support.apple.com/en-us/ht213055

Trust: 1.8

url:https://support.apple.com/en-us/ht213056

Trust: 1.8

url:https://support.apple.com/en-us/ht213057

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2022-22579

Trust: 1.3

url:https://support.apple.com/ht213055

Trust: 0.7

url:https://www.zerodayinitiative.com/advisories/zdi-22-361/

Trust: 0.7

url:https://packetstormsecurity.com/files/165774/apple-security-advisory-2022-01-26-4.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022012636

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-22579/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0408

Trust: 0.6

url:https://packetstormsecurity.com/files/165775/apple-security-advisory-2022-01-26-5.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0406

Trust: 0.6

url:https://vigilance.fr/vulnerability/apple-macos-multiple-vulnerabilities-37394

Trust: 0.6

url:https://support.apple.com/kb/ht201222

Trust: 0.5

url:https://www.apple.com/support/security/pgp/

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-22593

Trust: 0.5

url:https://xlab.tencent.com)

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2022-22585

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2022-22584

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22594

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22589

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22590

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22578

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22592

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22583

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-22587

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-30972

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/alphabugx/cve-2022-23305

Trust: 0.1

url:https://support.apple.com/ht213057.

Trust: 0.1

url:https://support.apple.com/ht213056.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-30946

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-30960

Trust: 0.1

url:https://support.apple.com/ht213055.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-22586

Trust: 0.1

url:https://support.apple.com/ht213054.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-22591

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://support.apple.com/ht213053.

Trust: 0.1

sources: ZDI: ZDI-22-361 // VULHUB: VHN-411207 // VULMON: CVE-2022-22579 // JVNDB: JVNDB-2022-008988 // PACKETSTORM: 165775 // PACKETSTORM: 165774 // PACKETSTORM: 165773 // PACKETSTORM: 165772 // PACKETSTORM: 165771 // CNNVD: CNNVD-202201-2416 // NVD: CVE-2022-22579

CREDITS

Mickey Jin (@patch1t) of Trend Micro

Trust: 1.3

sources: ZDI: ZDI-22-361 // CNNVD: CNNVD-202201-2416

SOURCES

db:ZDIid:ZDI-22-361
db:VULHUBid:VHN-411207
db:VULMONid:CVE-2022-22579
db:JVNDBid:JVNDB-2022-008988
db:PACKETSTORMid:165775
db:PACKETSTORMid:165774
db:PACKETSTORMid:165773
db:PACKETSTORMid:165772
db:PACKETSTORMid:165771
db:CNNVDid:CNNVD-202201-2416
db:NVDid:CVE-2022-22579

LAST UPDATE DATE

2024-08-14T13:11:22.805000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-22-361date:2022-02-16T00:00:00
db:VULHUBid:VHN-411207date:2022-03-28T00:00:00
db:VULMONid:CVE-2022-22579date:2023-08-08T00:00:00
db:JVNDBid:JVNDB-2022-008988date:2023-08-02T03:11:00
db:CNNVDid:CNNVD-202201-2416date:2022-12-09T00:00:00
db:NVDid:CVE-2022-22579date:2023-08-08T14:22:24.967

SOURCES RELEASE DATE

db:ZDIid:ZDI-22-361date:2022-02-16T00:00:00
db:VULHUBid:VHN-411207date:2022-03-18T00:00:00
db:VULMONid:CVE-2022-22579date:2022-03-18T00:00:00
db:JVNDBid:JVNDB-2022-008988date:2023-08-02T00:00:00
db:PACKETSTORMid:165775date:2022-01-31T15:46:53
db:PACKETSTORMid:165774date:2022-01-31T15:46:38
db:PACKETSTORMid:165773date:2022-01-31T15:46:23
db:PACKETSTORMid:165772date:2022-01-31T15:46:05
db:PACKETSTORMid:165771date:2022-01-31T15:45:47
db:CNNVDid:CNNVD-202201-2416date:2022-01-26T00:00:00
db:NVDid:CVE-2022-22579date:2022-03-18T18:15:12.273