CVE-2018-4124
Last modified
CVE-2018-4124 is a vulnerability of currently unknown severity. An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. EPSS estimates a 6.69% chance of exploitation in the next 30 days.
Description
An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a crafted string containing a certain Telugu character.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | < 11.2.6 |
| Apple | Mac Os X | < 10.13.3 |
| Apple | Tvos | < 11.2.6 |
| Apple | Watchos | < 4.2.3 |
References
- http://www.securitytracker.com/id/1040396Third Party Advisory, VDB Entry
- https://support.apple.com/HT208534Vendor Advisory
- https://support.apple.com/HT208535Vendor Advisory
- https://support.apple.com/HT208536Vendor Advisory
- https://support.apple.com/HT208537Vendor Advisory
- http://www.securitytracker.com/id/1040396Third Party Advisory, VDB Entry
- https://support.apple.com/HT208534Vendor Advisory
- https://support.apple.com/HT208535Vendor Advisory
- https://support.apple.com/HT208536Vendor Advisory
- https://support.apple.com/HT208537Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-4124?
How severe is CVE-2018-4124?
How do I fix CVE-2018-4124?
Are you affected by CVE-2018-4124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
