CERT-In Advisory
CIAD-2018-0020
Apple macOS / OS X Multiple Vulnerabilities
Original Issue Date: June 27, 2018
Severity Rating: High
Systems Affected
- Apple macOS Sierra 10.13.4
- Apple macOS Sierra 10.12.6
- OS X El Capitan 10.11.6
Overview
Multiple vulnerabilities have been reported in Apple macOS/OS X which could allow a remote attacker to execute arbitrary code, cause denial of service (DoS) conditions, gain potentially sensitive information, bypass security controls or obtain elevated privileges on a targeted system.
Description
These vulnerabilities are due to improper memory handling, insufficient validation of user-supplied input, improper security restrictions, and insufficient bounds checking by the affected software. A remote attacker could exploit these vulnerabilities by enticing a targeted user to open a specially crafted file or execute a malicious application.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, obtain sensitive information or cause Denial of Service (DoS) conditions, bypass security controls or obtain elevated privileges on a targeted system. on the targeted system.
Solution
Apply appropriate security updates as mentioned in the
Apple Security Advisory HT208849
Vendor Information
Apple
https://support.apple.com/en-us/HT208849
References
Apple
https://support.apple.com/en-us/HT208849
Security Tracker
https://securitytracker.com/id/1041027
CVE Name
CVE-2018-4141
CVE-2018-4159
CVE-2018-4171
CVE-2018-4184
CVE-2018-4193
CVE-2018-4196
CVE-2018-4198
CVE-2018-4202
CVE-2018-4211
CVE-2018-4219
CVE-2018-4221
CVE-2018-4223
CVE-2018-4224
CVE-2018-4225
CVE-2018-4226
CVE-2018-4227
CVE-2018-4228
CVE-2018-4229
CVE-2018-4230
CVE-2018-4234
CVE-2018-4235
CVE-2018-4236
CVE-2018-4237
CVE-2018-4240
CVE-2018-4241
CVE-2018-4242
CVE-2018-4243
CVE-2018-4249
CVE-2018-4251
CVE-2018-4253
CVE-2018-7584
CVE-2018-8897
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|