CVE-2018-4124

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a crafted string containing a certain Telugu character.

References

http://www.securitytracker.com/id/1040396

https://nakedsecurity.sophos.com/2018/02/20/apple-fixes-that-1-character-to-crash-your-mac-and-iphone-bug/

https://support.apple.com/HT208534

https://support.apple.com/HT208535

https://support.apple.com/HT208536

https://support.apple.com/HT208537

Details

Source: MITRE

Published: 2018-04-03

Updated: 2019-03-08

Type: CWE-119

Risk Information

CVSS v2

Base Score: 9

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C

Impact Score: 8.5

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (4 total)

IDNameProductFamilySeverity
700547Apple iOS < 11.2.6 Telugu Character Handling Remote Memory Corruption Vulnerability (APPLE-SA-2018-02-19-1)Nessus Network MonitorMobile Devices
high
107071macOS 10.13.3 Supplemental UpdateNessusMacOS X Local Security Checks
critical
106974Apple TV < 11.2.6 Telugu Character Handling Remote Memory Corruption VulnerabilityNessusMisc.
critical
106946Apple iOS < 11.2.6 Telugu Character Handling Remote Memory Corruption VulnerabilityNessusMobile Devices
critical