ID

VAR-201904-1455


CVE

CVE-2018-4403


TITLE

plural Apple Updates to product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2018-008908

DESCRIPTION

This issue was addressed by removing additional entitlements. This issue affected versions prior to macOS Mojave 10.14.1. Apple Has released an update for each product.The expected impact depends on each vulnerability, but can be affected as follows: Detail is Apple See the information provided by. * HTTP Through the client AFP Server attack * Arbitrary code execution * information leak * Buffer overflow * Privilege escalation * Service operation interruption (DoS) * File system tampering * UI Spoofing * Limit avoidance * Cross-site scripting * Address bar impersonation. macOS Contains an information disclosure vulnerability due to a flaw in handling additional entitlements.Information may be obtained. Apple macOS Mojave is a set of dedicated operating systems developed by Apple for Mac computers. The Dock is one of the graphical user interfaces used to start and switch running applications. This vulnerability stems from configuration errors in network systems or products during operation. An unauthorized attacker could exploit the vulnerability to obtain sensitive information of the affected components

Trust: 2.52

sources: NVD: CVE-2018-4403 // JVNDB: JVNDB-2018-008908 // JVNDB: JVNDB-2018-014976 // VULHUB: VHN-134434 // VULMON: CVE-2018-4403

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:ltversion:10.14.1

Trust: 1.0

vendor:applemodel:icloudscope:ltversion:for windows 7.8 earlier

Trust: 0.8

vendor:applemodel:iosscope:ltversion:12.1 earlier

Trust: 0.8

vendor:applemodel:itunesscope:ltversion:12.9.1 earlier

Trust: 0.8

vendor:applemodel:macos high sierrascope:eqversion:(security update 2018-001 not applied )

Trust: 0.8

vendor:applemodel:macos mojavescope:ltversion:10.14.1 earlier

Trust: 0.8

vendor:applemodel:macos sierrascope:eqversion:(security update 2018-005 not applied )

Trust: 0.8

vendor:applemodel:safariscope:ltversion:12.0.1 earlier

Trust: 0.8

vendor:applemodel:tvosscope:ltversion:12.1 earlier

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:5.1 earlier

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.14

Trust: 0.8

sources: JVNDB: JVNDB-2018-008908 // JVNDB: JVNDB-2018-014976 // NVD: CVE-2018-4403

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-4403
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-4403
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201810-1508
value: MEDIUM

Trust: 0.6

VULHUB: VHN-134434
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-4403
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-4403
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-134434
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-4403
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-134434 // VULMON: CVE-2018-4403 // JVNDB: JVNDB-2018-014976 // CNNVD: CNNVD-201810-1508 // NVD: CVE-2018-4403

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-134434 // JVNDB: JVNDB-2018-014976 // NVD: CVE-2018-4403

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201810-1508

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201810-1508

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-008908

PATCH

title:About the security content of macOS Mojave 10.14.1, Security Update 2018-001 High Sierra, Security Update 2018-005 Sierraurl:https://support.apple.com/en-us/HT209193

Trust: 1.6

title:About the security content of iTunes 12.9.1url:https://support.apple.com/en-us/HT209197

Trust: 0.8

title: About the security content of iCloud for Windows 7.8 url:https://support.apple.com/en-us/HT209198

Trust: 0.8

title:About the security content of Safari 12.0.1url:https://support.apple.com/en-us/HT209196

Trust: 0.8

title: About the security content of tvOS 12.1url:https://support.apple.com/en-us/HT209194

Trust: 0.8

title: About the security content of iOS 12.1url:https://support.apple.com/en-us/HT209192

Trust: 0.8

title: About the security content of watchOS 5.1url:https://support.apple.com/en-us/HT209195

Trust: 0.8

title:HT209193url:https://support.apple.com/ja-jp/HT209193

Trust: 0.8

title:Apple macOS Mojave Dock Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=86487

Trust: 0.6

sources: JVNDB: JVNDB-2018-008908 // JVNDB: JVNDB-2018-014976 // CNNVD: CNNVD-201810-1508

EXTERNAL IDS

db:NVDid:CVE-2018-4403

Trust: 2.6

db:JVNid:JVNVU96365720

Trust: 1.6

db:JVNDBid:JVNDB-2018-008908

Trust: 0.8

db:JVNDBid:JVNDB-2018-014976

Trust: 0.8

db:CNNVDid:CNNVD-201810-1508

Trust: 0.7

db:VULHUBid:VHN-134434

Trust: 0.1

db:VULMONid:CVE-2018-4403

Trust: 0.1

sources: VULHUB: VHN-134434 // VULMON: CVE-2018-4403 // JVNDB: JVNDB-2018-008908 // JVNDB: JVNDB-2018-014976 // CNNVD: CNNVD-201810-1508 // NVD: CVE-2018-4403

REFERENCES

url:https://support.apple.com/kb/ht209193

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-4403

Trust: 1.4

url:https://jvn.jp/vu/jvnvu96365720/

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4403

Trust: 0.8

url:https://jvn.jp/vu/jvnvu96365720/index.html

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://seclists.org/fulldisclosure/2018/nov/10

Trust: 0.1

sources: VULHUB: VHN-134434 // VULMON: CVE-2018-4403 // JVNDB: JVNDB-2018-008908 // JVNDB: JVNDB-2018-014976 // CNNVD: CNNVD-201810-1508 // NVD: CVE-2018-4403

CREDITS

Patrick Wardle of Digita Security,Jeff Johnson of underpassapp.com

Trust: 0.6

sources: CNNVD: CNNVD-201810-1508

SOURCES

db:VULHUBid:VHN-134434
db:VULMONid:CVE-2018-4403
db:JVNDBid:JVNDB-2018-008908
db:JVNDBid:JVNDB-2018-014976
db:CNNVDid:CNNVD-201810-1508
db:NVDid:CVE-2018-4403

LAST UPDATE DATE

2024-11-23T19:42:36.783000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-134434date:2019-04-05T00:00:00
db:VULMONid:CVE-2018-4403date:2019-04-05T00:00:00
db:JVNDBid:JVNDB-2018-008908date:2018-11-01T00:00:00
db:JVNDBid:JVNDB-2018-014976date:2019-04-18T00:00:00
db:CNNVDid:CNNVD-201810-1508date:2019-04-10T00:00:00
db:NVDid:CVE-2018-4403date:2024-11-21T04:07:20.810

SOURCES RELEASE DATE

db:VULHUBid:VHN-134434date:2019-04-03T00:00:00
db:VULMONid:CVE-2018-4403date:2019-04-03T00:00:00
db:JVNDBid:JVNDB-2018-008908date:2018-11-01T00:00:00
db:JVNDBid:JVNDB-2018-014976date:2019-04-18T00:00:00
db:CNNVDid:CNNVD-201810-1508date:2018-10-31T00:00:00
db:NVDid:CVE-2018-4403date:2019-04-03T18:29:13.550