Improper input validation in Apple Safari - CVE-2018-4232

 

Improper input validation in Apple Safari - CVE-2018-4232

Published: June 4, 2018


Vulnerability identifier: #VU13143
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4232
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote unauthenticated attacker can trick the victim into visiting a specially crafted website, bypass security restrictions and cause cookies to be overwritten.


Affected software

Apple Safari
Gentoo Linux
tvOS
Apple iOS
Opensuse
Ubuntu
Fedora
iCloud for Windows
iTunes
webkitgtk4
webkit2gtk3

How to mitigate CVE-2018-4232

Update to version 11.1.1.

webkitgtk4 - update to 2.20.3-1.fc27
webkit2gtk3 - update to 2.20.3-1.fc28

External References

Related Security Bulletins