CVE-2017-13812 is a memory corruption vulnerability in the libarchive component of macOS versions prior to 10.13.1. This flaw allows remote attackers to execute arbitrary code or trigger a denial of service by enticing a user to open a specially crafted archive file. Rated 7.8 HIGH on CVSS, it requires user interaction and local access for exploitation, potentially leading to high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code is reported, and community discussion is minimal, the vulnerability poses a significant risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.13.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.