Synopsis
The remote host is running a version of Apple TV that is affected by multiple attack vectors.
Description
Versions of Apple TV earlier than 10.2.1 are affected by multiple vulnerabilities :
- A flaw exists that is triggered as certain input is not properly validated. This may allow a context-dependent attacker to corrupt memory and potentially execute arbitrary code.
- A use-after-free error exists in the handling of RenderLayer objects. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
- A logic flaw exists that allows a universal cross-site scripting (UXSS) attack. The issue is triggered when handling WebKit Editor commands. This may allow a context-dependent attacker to create a specially crafted web page that will execute arbitrary script code in a user's browser session within the trust relationship between their browser and any website.
This product is also affected by vulnerabilities found in the following components:
- AVEVideoEncoder
- CoreAudio
- CoreFoundation
- Foundation
- IOSurface
- Kernel
- SQLite
- TextInput
- WebKit
- Web Inspector
Solution
Upgrade Apple TV to 10.2.1, or later.