CERT-In Advisory
CIAD-2019-0032
Apple macOS /OS X Multiple Vulnerabilities
Original Issue Date: October 04, 2019
Severity Rating: High
Software Affected
- Apple macOS Sierra 10.13.5
- Apple macOS Sierra 10.12.6
- OS X El Capitan 10.11.6
Overview
Multiple vulnerabilities have been reported in Apple macOS/OS X which could allow a remote attacker to gain potentially sensitive information, bypass security controls and obtain elevated privileges on a targeted system.
Description
These vulnerabilities are due to improper memory handling, insufficient validation of user-supplied input, improper security restrictions, and insufficient bounds checking in IOGraphics,AMD, APFS, ATS, CoreCrypto, DesktopServices components of Apple macOS. A remote attacker could exploit these vulnerabilities by enticing a targeted user to open a specially crafted file or execute a malicious application.
Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive information, bypass security controls and obtain elevated privileges on a targeted system on the targeted system.
Solution
Apply appropriate security updates as mentioned in the in the
Apple Security Advisory HT208937
Vendor Information
Apple
https://support.apple.com/en-us/HT208937
References
Apple
https://support.apple.com/en-us/HT208937
Security Tracker
https://securitytracker.com/id/1041233
CVE Name
CVE-2018-4178
CVE-2018-4268
CVE-2018-4269
CVE-2018-4283
CVE-2018-4285
CVE-2018-4289
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|