#VU31123 Buffer overflow in tvOS - CVE-2018-4145
Published: April 3, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU31123
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-4145
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
tvOS
tvOS
Software vendor:
Apple Inc.
Apple Inc.
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.
Remediation
Install update from vendor's website.