Out-of-bounds read in Apple Safari - CVE-2018-4222
Published: June 4, 2018
Vulnerability identifier: #VU13145
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-4222
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds read error in WebKit. A remote unauthenticated attacker can trick the victim into loading a specially crafted content, trigger memory corruption and cause the service to crash.
Affected software
Apple Safari
Gentoo Linux
watchOS
tvOS
Apple iOS
Opensuse
Ubuntu
Fedora
iCloud for Windows
iTunes
webkitgtk4
webkit2gtk3
Gentoo Linux
watchOS
tvOS
Apple iOS
Opensuse
Ubuntu
Fedora
iCloud for Windows
iTunes
webkitgtk4
webkit2gtk3
How to mitigate CVE-2018-4222
Update to version 11.1.1.
webkitgtk4 - update to 2.20.3-1.fc27
webkit2gtk3 - update to 2.20.3-1.fc28
webkit2gtk3 - update to 2.20.3-1.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iTunes
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple iCloud
- Multiple vulnerabilities in Apple iOS
- Ubuntu update for Webkit2gtk
- OpenSUSE Linux update for webkit2gtk3
- Gentoo update for WebkitGTK+
- OpenSUSE Linux update for webkit2gtk3
- Fedora 27 update for webkitgtk4
- Fedora 28 update for webkit2gtk3