CERT-In Advisory
CIAD-2018-0032
Multiple Vulnerabilities in Apple iOS
Original Issue Date: November 16, 2018
Severity Rating: High
Software Affected
- Apple iOS versions prior to 12.1
Overview
Multiple vulnerabilities have been reported in the different components of Apple iOS which could be exploited by an attacker to cause arbitrary code execution , denial of service (DoS) condition, cross site scripting attacks , gain elevated privilege , read privileged memory and obtain potentially sensitive information on the target system.
Description
The vulnerabilities are due to the memory corruption issues, improper input validation, out-of-bounds read flaw, exploitation of the Miller-Rabin primarily test weakness, restricted files access, privilege escalation flaws, buffer overflow issues, security restrictions bypass and information disclosure flaw.
Successful exploitation of some these vulnerabilities could also allow the attacker to cause user interface spoofing when processing a maliciously crafted mail message.
Solution
Upgrade to Apple iOS version 12.1 Apple Security Advisory
https://support.apple.com/en-us/HT209192
Vendor Information
Apple
https://support.apple.com/en-us/HT209192
References
Apple
https://support.apple.com/en-us/HT209192
Security Tracker
https://securitytracker.com/id/1042003
Center for Internet security
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-apple-products-could-allow-for-arbitrary-code-execution_2018-120/
CVE Name
CVE-2018-4365
CVE-2018-4366
CVE-2018-4367
CVE-2018-4368
CVE-2018-4369
CVE-2018-4371
CVE-2018-4372
CVE-2018-4373
CVE-2018-4374
CVE-2018-4375
CVE-2018-4376
CVE-2018-4378
CVE-2018-4382
CVE-2018-4384
CVE-2018-4385
CVE-2018-4386
CVE-2018-4387
CVE-2018-4388
CVE-2018-4390
CVE-2018-4391
CVE-2018-4392
CVE-2018-4394
CVE-2018-4398
CVE-2018-4400
CVE-2018-4409
CVE-2018-4413
CVE-2018-4416
CVE-2018-4419
CVE-2018-4420
CVE-2018-4427
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|