ID

VAR-202109-1333


CVE

CVE-2021-30718


TITLE

Pillow Buffer error vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202104-975

DESCRIPTION

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A non-privileged user may be able to modify restricted settings. Pillow is a Python-based image processing library. There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. An access control bug exists in macOS Big Sur that stems from allowing local users to gain unauthorized access to otherwise restricted functionality. Affected versions: macOS: 11.0 20A2411, 11.0.1 20B29, 11.0.1 20B50, 11.1 20C69, 11.2 20D64, 11.2.1 20D74, 11.2.1 20D75, 11.2.2 20D80, 11.2.3 20D91, 1E2.3, 20D91, 11.2.3, 20D74 20E241

Trust: 1.62

sources: NVD: CVE-2021-30718 // CNNVD: CNNVD-202104-975 // VULHUB: VHN-390451 // VULMON: CVE-2021-30718

AFFECTED PRODUCTS

vendor:applemodel:macosscope:gteversion:11.0

Trust: 1.0

vendor:applemodel:macosscope:ltversion:11.4

Trust: 1.0

sources: NVD: CVE-2021-30718

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-30718
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202104-975
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202105-1445
value: MEDIUM

Trust: 0.6

VULHUB: VHN-390451
value: MEDIUM

Trust: 0.1

VULMON: CVE-2021-30718
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-30718
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-390451
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-30718
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-390451 // VULMON: CVE-2021-30718 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1445 // NVD: CVE-2021-30718

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2021-30718

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202105-1445

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202104-975

PATCH

title:Apple macOS Big Sur Fixes for access control error vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=151638

Trust: 0.6

sources: CNNVD: CNNVD-202105-1445

EXTERNAL IDS

db:NVDid:CVE-2021-30718

Trust: 1.8

db:CS-HELPid:SB2021041363

Trust: 0.6

db:CNNVDid:CNNVD-202104-975

Trust: 0.6

db:AUSCERTid:ESB-2021.1794

Trust: 0.6

db:CS-HELPid:SB2021052415

Trust: 0.6

db:CNNVDid:CNNVD-202105-1445

Trust: 0.6

db:VULHUBid:VHN-390451

Trust: 0.1

db:VULMONid:CVE-2021-30718

Trust: 0.1

sources: VULHUB: VHN-390451 // VULMON: CVE-2021-30718 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1445 // NVD: CVE-2021-30718

REFERENCES

url:https://support.apple.com/en-us/ht212529

Trust: 1.8

url:https://www.cybersecurity-help.cz/vdb/sb2021041363

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021052415

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.1794

Trust: 0.6

url:https://vigilance.fr/vulnerability/apple-macos-multiple-vulnerabilities-35514

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2021-30718

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://seclists.org/fulldisclosure/2021/may/70

Trust: 0.1

sources: VULHUB: VHN-390451 // VULMON: CVE-2021-30718 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1445 // NVD: CVE-2021-30718

SOURCES

db:VULHUBid:VHN-390451
db:VULMONid:CVE-2021-30718
db:CNNVDid:CNNVD-202104-975
db:CNNVDid:CNNVD-202105-1445
db:NVDid:CVE-2021-30718

LAST UPDATE DATE

2024-08-14T12:11:16.702000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-390451date:2021-09-16T00:00:00
db:VULMONid:CVE-2021-30718date:2021-09-16T00:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-14T00:00:00
db:CNNVDid:CNNVD-202105-1445date:2021-09-18T00:00:00
db:NVDid:CVE-2021-30718date:2021-09-16T15:08:05.427

SOURCES RELEASE DATE

db:VULHUBid:VHN-390451date:2021-09-08T00:00:00
db:VULMONid:CVE-2021-30718date:2021-09-08T00:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-13T00:00:00
db:CNNVDid:CNNVD-202105-1445date:2021-05-24T00:00:00
db:NVDid:CVE-2021-30718date:2021-09-08T15:15:16.137