Information disclosure in Apple iOS - CVE-2018-4117

 

Information disclosure in Apple iOS - CVE-2018-4117

Published: March 30, 2018


Vulnerability identifier: #VU11411
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4117
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to input validation flaw in the WebKit component fetch API. A remote attacker can bypass cross-origin restrictions and obtain potentially sensitive information.

Affected software

Apple iOS
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
SUSE Linux
Opensuse
Google Chrome
chromium

How to mitigate CVE-2018-4117

Update to version 11.3.

Google Chrome - update to 68.0.3440.75
chromium - addressed in versions 68.0.3440.106-3.el7, 68.0.3440.106-3.fc27, 68.0.3440.106-3.fc28

External References

Related Security Bulletins