| CERT-In Advisory  
                                                                      CIAD-2018-0032Multiple Vulnerabilities in Apple iOSOriginal Issue Date: November  16, 2018
 Severity Rating: High
 Software Affected  
Apple iOS versions prior to 12.1  Overview Multiple vulnerabilities have been reported in the different components of Apple iOS which could be exploited by an attacker to cause arbitrary code execution , denial of service (DoS) condition, cross site scripting attacks , gain elevated privilege , read privileged memory and obtain potentially sensitive information on the target system. DescriptionThe vulnerabilities are due to the memory corruption issues, improper input validation, out-of-bounds read flaw, exploitation of the Miller-Rabin primarily test weakness, restricted files access, privilege escalation flaws, buffer overflow issues, security restrictions bypass and information disclosure flaw. 
 Successful exploitation of some these vulnerabilities could also allow the attacker to cause user interface spoofing when processing a maliciously crafted mail message.
 
 
 Solution Upgrade to Apple iOS version 12.1  Apple Security Advisory https://support.apple.com/en-us/HT209192
 
 Vendor InformationApple https://support.apple.com/en-us/HT209192
 
 References Applehttps://support.apple.com/en-us/HT209192
 
 Security Trackerhttps://securitytracker.com/id/1042003
 
 Center for Internet securityhttps://www.cisecurity.org/advisory/multiple-vulnerabilities-in-apple-products-could-allow-for-arbitrary-code-execution_2018-120/
 
 CVE NameDisclaimerCVE-2018-4365
 CVE-2018-4366
 CVE-2018-4367
 CVE-2018-4368
 CVE-2018-4369
 CVE-2018-4371
 CVE-2018-4372
 CVE-2018-4373
 CVE-2018-4374
 CVE-2018-4375
 CVE-2018-4376
 CVE-2018-4378
 CVE-2018-4382
 CVE-2018-4384
 CVE-2018-4385
 CVE-2018-4386
 CVE-2018-4387
 CVE-2018-4388
 CVE-2018-4390
 CVE-2018-4391
 CVE-2018-4392
 CVE-2018-4394
 CVE-2018-4398
 CVE-2018-4400
 CVE-2018-4409
 CVE-2018-4413
 CVE-2018-4416
 CVE-2018-4419
 CVE-2018-4420
 CVE-2018-4427
 
 The information provided herein is on "as is" basis, without warranty of any kind. Contact Information Email: info@cert-in.org.in  Phone: +91-11-24368572Postal address Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |