CVE-2022-42801 – XNU vm_object Use-After-Free
https://notcve.org/view.php?id=CVE-2022-42801
A logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1. An app may be able to execute arbitrary code with kernel privileges. Se solucionó un problema de lógica con controles mejorados. Este problema se solucionó en tvOS 16.1, iOS 15.7.1 y iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 y iPadOS 16, macOS Monterey 12.6.1. • http://packetstormsecurity.com/files/170011/XNU-vm_object-Use-After-Free.html https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213489 https://support.apple.com/en-us/HT213490 https://support.apple.com/en-us/HT213491 https://support.apple.com/en-us/HT213492 https://support.apple.com/en-us/HT213494 •
CVE-2022-42798 – Apple macOS AudioToolbox CAF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2022-42798
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. Parsing a maliciously crafted audio file may lead to disclosure of user information. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en tvOS 16.1, iOS 15.7.1 y iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 y iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. • https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213489 https://support.apple.com/en-us/HT213490 https://support.apple.com/en-us/HT213491 https://support.apple.com/en-us/HT213492 https://support.apple.com/en-us/HT213493 https://support.apple.com/en-us/HT213494 •
CVE-2022-32923 – webkitgtk: correctness issue in the JIT was addressed with improved checks
https://notcve.org/view.php?id=CVE-2022-32923
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app. Se solucionó un problema de corrección en el JIT mejorando los controles. Este problema se solucionó en tvOS 16.1, iOS 15.7.1 y iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 y iPadOS 16. • http://www.openwall.com/lists/oss-security/2022/11/04/4 https://security.gentoo.org/glsa/202305-32 https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213489 https://support.apple.com/en-us/HT213490 https://support.apple.com/en-us/HT213491 https://support.apple.com/en-us/HT213492 https://support.apple.com/en-us/HT213495 https://access.redhat.com/security/cve/CVE-2022-32923 https://bugzilla.redhat.com/show_bug.cgi?id=2140502 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2022-42825
https://notcve.org/view.php?id=CVE-2022-42825
This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system. Este problema se solucionó eliminando derechos adicionales. Este problema se solucionó en tvOS 16.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 y iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. • https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213489 https://support.apple.com/en-us/HT213491 https://support.apple.com/en-us/HT213492 https://support.apple.com/en-us/HT213493 https://support.apple.com/en-us/HT213494 •
CVE-2022-32862
https://notcve.org/view.php?id=CVE-2022-32862
This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1. An app with root privileges may be able to access private information. Este problema se solucionó mejorando la protección de datos. Este problema se solucionó en macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1. • https://github.com/rohitc33/CVE-2022-32862 https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213493 https://support.apple.com/en-us/HT213494 •