VulnerabilityModified
CVE-2023-41983
Processing web content may lead to a denial-of-service.
MEDIUM 6.5EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · fedoraproject/fedora · debian/debian linux
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2023/Oct/19Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/23Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/24Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/27Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/15/1Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RPPMOWFYZODONTA3RLZOKSGNR4DELGG2/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3O7ITSBZDHLBM5OG22K6RZAHRRTGECM/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K/Mailing List
- https://security.gentoo.org/glsa/202401-33
- https://support.apple.com/en-us/HT213981Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213982Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213984Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213986Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213984Vendor Advisory
- https://www.debian.org/security/2023/dsa-5557Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/19Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/23Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/24Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/27Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/15/1Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RPPMOWFYZODONTA3RLZOKSGNR4DELGG2/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3O7ITSBZDHLBM5OG22K6RZAHRRTGECM/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTCZGQPRDAOPP6NK4CIDJKIPMBWD5J7K/Mailing List
- https://security.gentoo.org/glsa/202401-33
- https://support.apple.com/en-us/HT213981Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213982Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213984Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213986Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213984Vendor Advisory
- https://www.debian.org/security/2023/dsa-5557Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.