Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2022.5793 APPLE-SA-2022-11-09-2 macOS Ventura 13.0.1 10 November 2022 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: macOS Ventura 13.0.1 Publisher: Apple Operating System: macOS Resolution: Patch/Upgrade CVE Names: CVE-2022-40304 CVE-2022-40303 Original Bulletin: https://support.apple.com/HT213504 Comment: CVSS (Max): 8.2 CVE-2022-40304 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H) CVSS Source: Red Hat Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2022-11-09-2 macOS Ventura 13.0.1 macOS Ventura 13.0.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213504. libxml2 Available for: macOS Ventura Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution Description: An integer overflow was addressed through improved input validation. CVE-2022-40303: Maddie Stone of Google Project Zero libxml2 Available for: macOS Ventura Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution Description: This issue was addressed with improved checks. CVE-2022-40304: Ned Williamson and Nathan Wachholz of Google Project Zero All information is also posted on the Apple Security Updates web site: https://support.apple.com/en-us/HT201222. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEBP+4DupqR5Sgt1DB4RjMIDkeNxkFAmNsFNQACgkQ4RjMIDke NxkkbBAAsAYMux+v/27NK6+FvyxrTRLkR0yyzp8SorMSfPwZInNGkkEmQxjSzI0+ D3rK9usf/pouEV9LMnR+Uf37pEdlpSDD7uXZ81m1vhN6RPkz2qD5WdM46RaWTbAS /xe3ZEu8+Jpr5SQSWuI+QIBr/vn9Txu/N6l/WQVxnWS+RSWO6tZLLOXMEyVk9vPx XJGyQywt3XYoVksvzwAgm/2yslQ+0OWphWjLp73bjQGrrIiClphxmtyvA0SN8Nds Ah0+X8SRjCErSN4736U1htKtClSHDowdaD2wevGGUrdRSLJQLTPPkqUPF3P/4/8i xW42Zgf9qucN9O89P7ONvHOIe8swtD9vf1AjFXvsDqQvMZQVFDBNXbG138V4LLws f5UdpUmY/0lSnVpAZQlo+xuMJSb3SMWYIB2ozhzDLHgBKTxERFB7uyrEYQgXs9XB 1qg+BbW5uooEoMKbutw36/II/JTFRM34QxWiOJHw4cCypmuaGkSJ/8jsTJDlRvG/ T9BchgHjBvqHFtCVNLGikkVYzEVQnQLXQAZoZMCYV0benebEIFLIaObaciQqA3F2 N7/rvpXd5l6G3sEGwqMPT5aYj6Vm/0LBnxuTlN1xN1wgOQoS+LWL8bW+8/HjtJLa eyWMh8yD0o02Hf6dNIl9RTuoAKwZvmJbeqi/1uEaoL8sAP9gK1s= =CjcG - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBY2yVl8kNZI30y1K9AQh66hAAn2fzX4ayGU1CEjBckDBQY8wip0brUlgS If3Ou0Ysb3u5vSQgqzxNG92AZqbzwdxZlgxv/1HNkQIuqp5dr3Wh+R3tAe0ayxPU 2ma/4jT1x4f+nw08htsRuV9bUHcKKutxPweMbyRMwoqI9MQ8g64wjnM6ouJiTME9 rSBfStdvgD6z0ccPOIxtyBx4RDuk7RSVSieElpCAlxqFmsei5OyGWCyoVUkQW/tr Mu+YaiBLpkikQ/EVIHmhsMOYLLPsipE+V/RV6r23rZTW3TkkYotnwC46yaL/vO7V HrnjcXKl830f8IFi/d6Qcy+GcX6TUt2sFXTbtSsQcXg6ikZYPyOuYNl2Xj6oWi2x Kba9VVO6OUR8aOKw8GyNoY4EH7RklSalwhiWYczUvGkh7mY6RBJg92ymLDXuBe5q d16jtZ7XGVEfMLxxgIBGgcJJtt0A7LX53+GQFw1dh304mJl1cXxZWGUqjp7jsnVV QYauntcJ527zJXe+1IML2vIs0Dv37+B//OH6SIeGKFTXK008MRQ/+QS+oZEsb/9l 13a6+dj4PmWKXdu778FojrcUq5glC4qnCJPdaMOKRLY7i3wUxsUZo1ROY8QeqNCK rCsgpzGCJ0QFKy6FNAoOR8cNJaAm0dH7BhgaHzRhxZ/InwgR2iwIun2KHVW0IL6s WtOAQ3B9nqo= =6x7q -----END PGP SIGNATURE-----