SQL injection in Apple iOS - CVE-2018-20506

 

SQL injection in Apple iOS - CVE-2018-20506

Published: January 23, 2019 / Updated: January 29, 2019


Vulnerability identifier: #VU17164
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20506
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in the SQLite component. A remote attacker can send a specially specially crafted request to the affected application and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.


Affected software

Apple iOS
watchOS
macOS
tvOS
Opensuse
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Dell PowerProtect Cyber Recovery
sqlite3 (Ubuntu package)
iCloud for Windows
iTunes
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2018-20506

Update to version 12.1.3.

Apple iOS - update to 12.1.3 16D39
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
sqlite3 (Ubuntu package) - addressed in versions 3.11.0-1ubuntu1.2, 3.22.0-1ubuntu0.1, 3.24.0-1ubuntu0.1, 3.27.2-2ubuntu0.1
watchOS - update to 5.1.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
iCloud for Windows - update to 7.10
macOS - update to 10.14.3 18D42
tvOS - update to 12.1.2
iTunes - update to 12.9.3
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins