ID

VAR-201904-1467


CVE

CVE-2018-4353


TITLE

macOS Configuration vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-015004

DESCRIPTION

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14. macOS Has a configuration vulnerability due to flaws in handling restrictions.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Apple From macOS An update for has been released.The potential impact depends on each vulnerability, but may be affected as follows: * Arbitrary code execution * information leak * Access restriction bypass. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-9-24-1 macOS Mojave 10.14 macOS Mojave 10.14 is now available and addresses the following: Bluetooth Available for: iMac (21.5-inch, Late 2012), iMac (27-inch, Late 2012) , iMac (21.5-inch, Late 2013), iMac (21.5-inch, Mid 2014), iMac (Retina 5K, 27-inch, Late 2014), iMac (21.5-inch, Late 2015), Mac mini (Mid 2011), Mac mini Server (Mid 2011), Mac mini (Late 2012) , Mac mini Server (Late 2012), Mac mini (Late 2014), Mac Pro (Late 2013), MacBook Air (11-inch, Mid 2011), MacBook Air (13-inch, Mid 2011), MacBook Air (11-inch, Mid 2012), MacBook Air (13-inch, Mid 2012), MacBook Air (11-inch, Mid 2013), MacBook Air (13-inch, Mid 2013), MacBook Air (11-inch, Early 2015), MacBook Air (13-inch, Early 2015), MacBook Pro (13-inch, Mid 2012), MacBook Pro (15-inch, Mid 2012), MacBook Pro (Retina, 13-inch, Early 2013), MacBook Pro (Retina, 15-inch, Early 2013), MacBook Pro (Retina, 13-inch, Late 2013), and MacBook Pro (Retina, 15-inch, Late 2013) Impact: An attacker in a privileged network position may be able to intercept Bluetooth traffic Description: An input validation issue existed in Bluetooth. CVE-2018-5383: Lior Neumann and Eli Biham The updates below are available for these Mac models: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013, Mid 2010, and Mid 2012 models with recommended Metal-capable graphics processor, including MSI Gaming Radeon RX 560 and Sapphire Radeon PULSE RX 580) App Store Impact: A malicious application may be able to determine the Apple ID of the owner of the computer Description: A permissions issue existed in the handling of the Apple ID. CVE-2018-4324: Sergii Kryvoblotskyi of MacPaw Inc. CVE-2018-4353: Abhinav Bansal of Zscaler, Inc. Auto Unlock Impact: A malicious application may be able to access local users AppleIDs Description: A validation issue existed in the entitlement verification. CVE-2018-4321: Min (Spark) Zheng, Xiaolong Bai of Alibaba Inc. Crash Reporter Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization. CVE-2018-4333: Brandon Azad Kernel Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2018-4336: Brandon Azad CVE-2018-4344: The UK's National Cyber Security Centre (NCSC) Security Impact: An attacker may be able to exploit weaknesses in the RC4 cryptographic algorithm Description: This issue was addressed by removing RC4. CVE-2016-1777: Pepi Zawodsky Accessibility Framework We would like to acknowledge Ryan Govostes for their assistance. Additional recognition Core Data We would like to acknowledge Andreas Kurtz (@aykay) of NESO Security Labs GmbH for their assistance. CoreGraphics We would like to acknowledge Nitin Arya of Roblox Corporation for their assistance. Mail We would like to acknowledge Alessandro Avagliano of Rocket Internet SE, John Whitehead of The New York Times, Kelvin Delbarre of Omicron Software Systems, and Zbyszek A>>A3Akiewski for their assistance. Security We would like to acknowledge Christoph Sinai, Daniel Dudek (@dannysapples) of The Irish Times and Filip KlubiAka (@lemoncloak) of ADAPT Centre, Dublin Institute of Technology, Istvan Csanady of Shapr3D, Omar Barkawi of ITG Software, Inc., Phil Caleno, Wilson Ding, and an anonymous researcher for their assistance. SQLite We would like to acknowledge Andreas Kurtz (@aykay) of NESO Security Labs GmbH for their assistance. Installation note: macOS Mojave 10.14 may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlupFUIACgkQeC9tht7T K3FSKQ//YXQwJ6lpCD/rqdM/MAa4eZ4y/vyyhMc0t9Q32smmeFEPuM2MG3+Sh7Xc c2nAgTBDu5NdLvY1qxIsHV+NINHJZexTX5kOBqzY5YL5peYDAdaBINwDMzfuNQHD L6X3gtbOXrsAsfdJHZaV+GyEqPaJ65fdWxuql3g3ecXKDCzYF1Gb9FUhyvTHYm+I Uwqn5rBtgviAYyHAr5RAl8J4G8yshp4sdw3gKeQ9xxcrhfhRKbTOQCVdXcjXInh+ asC07y843MYc5rdp8WWKO5yPmg6frj8ss1cp3zRVQCk41WTsfwI319I63GvGAEZA nvMLxs16y8Wp8dPCQBUBuC0Pr+PvWWzA8CFv7feFcgylectrOQjNlg1ybRlg6org 4QPL6vGfo1dQJ4F3t+h7VnOaKulD83UyGkI+DtSMvqEJyvYnOg3tmbI1pv8lHu9c ZTWrCxpm59KOGYi9ODJ1dzqUIWcrPQBmJa1eN5ZaFOl2/QVmrVztvplV9CvChVte w/TqWlcdvBt4z4LE9yCua82TtRxy4vWbSU/xYILGixJjBjK+ff4mEZGXul8A7yV9 lhhGENXrwgEYUHcnMkTTvSdHg8ASuCVvbn+2EgoyykWnwUjlxqzm0pukMB9Uq/wm IHV+qibDoI4szssR0nx9IHv+YeG7HZdq6599PRnF2/xiXwJKcLE= =EzzA -----END PGP SIGNATURE-----

Trust: 2.61

sources: NVD: CVE-2018-4353 // JVNDB: JVNDB-2018-015004 // JVNDB: JVNDB-2018-007762 // VULHUB: VHN-134384 // VULMON: CVE-2018-4353 // PACKETSTORM: 149510

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:ltversion:10.14

Trust: 1.8

vendor:applemodel:macos mojavescope:ltversion:10.14 earlier

Trust: 0.8

sources: JVNDB: JVNDB-2018-015004 // JVNDB: JVNDB-2018-007762 // NVD: CVE-2018-4353

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-4353
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-4353
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201809-1171
value: CRITICAL

Trust: 0.6

VULHUB: VHN-134384
value: HIGH

Trust: 0.1

VULMON: CVE-2018-4353
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-4353
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-134384
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-4353
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-134384 // VULMON: CVE-2018-4353 // JVNDB: JVNDB-2018-015004 // CNNVD: CNNVD-201809-1171 // NVD: CVE-2018-4353

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-134384 // JVNDB: JVNDB-2018-015004 // NVD: CVE-2018-4353

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201809-1171

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201809-1171

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015004

PATCH

title:HT209139url:https://support.apple.com/en-us/HT209139

Trust: 1.6

title:HT209139url:https://support.apple.com/ja-jp/HT209139

Trust: 0.8

title:Apple macOS Mojave Application Firewall Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=85205

Trust: 0.6

sources: JVNDB: JVNDB-2018-015004 // JVNDB: JVNDB-2018-007762 // CNNVD: CNNVD-201809-1171

EXTERNAL IDS

db:NVDid:CVE-2018-4353

Trust: 2.7

db:JVNid:JVNVU99356481

Trust: 1.6

db:JVNDBid:JVNDB-2018-015004

Trust: 0.8

db:JVNDBid:JVNDB-2018-007762

Trust: 0.8

db:CNNVDid:CNNVD-201809-1171

Trust: 0.6

db:VULHUBid:VHN-134384

Trust: 0.1

db:VULMONid:CVE-2018-4353

Trust: 0.1

db:PACKETSTORMid:149510

Trust: 0.1

sources: VULHUB: VHN-134384 // VULMON: CVE-2018-4353 // JVNDB: JVNDB-2018-015004 // JVNDB: JVNDB-2018-007762 // PACKETSTORM: 149510 // CNNVD: CNNVD-201809-1171 // NVD: CVE-2018-4353

REFERENCES

url:https://support.apple.com/kb/ht209139

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-4353

Trust: 1.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4353

Trust: 0.8

url:https://jvn.jp/vu/jvnvu99356481/index.html

Trust: 0.8

url:https://jvn.jp/vu/jvnvu99356481/

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/20.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://seclists.org/bugtraq/2018/sep/65

Trust: 0.1

url:https://support.apple.com/kb/ht201222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4333

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4336

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4324

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4321

Trust: 0.1

url:https://support.apple.com/downloads/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4344

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1777

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-5383

Trust: 0.1

sources: VULHUB: VHN-134384 // VULMON: CVE-2018-4353 // JVNDB: JVNDB-2018-015004 // JVNDB: JVNDB-2018-007762 // PACKETSTORM: 149510 // CNNVD: CNNVD-201809-1171 // NVD: CVE-2018-4353

CREDITS

Apple

Trust: 0.1

sources: PACKETSTORM: 149510

SOURCES

db:VULHUBid:VHN-134384
db:VULMONid:CVE-2018-4353
db:JVNDBid:JVNDB-2018-015004
db:JVNDBid:JVNDB-2018-007762
db:PACKETSTORMid:149510
db:CNNVDid:CNNVD-201809-1171
db:NVDid:CVE-2018-4353

LAST UPDATE DATE

2024-11-23T20:30:15.593000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-134384date:2019-04-08T00:00:00
db:VULMONid:CVE-2018-4353date:2019-04-08T00:00:00
db:JVNDBid:JVNDB-2018-015004date:2019-04-18T00:00:00
db:JVNDBid:JVNDB-2018-007762date:2018-09-26T00:00:00
db:CNNVDid:CNNVD-201809-1171date:2019-04-09T00:00:00
db:NVDid:CVE-2018-4353date:2024-11-21T04:07:15.047

SOURCES RELEASE DATE

db:VULHUBid:VHN-134384date:2019-04-03T00:00:00
db:VULMONid:CVE-2018-4353date:2019-04-03T00:00:00
db:JVNDBid:JVNDB-2018-015004date:2019-04-18T00:00:00
db:JVNDBid:JVNDB-2018-007762date:2018-09-26T00:00:00
db:PACKETSTORMid:149510date:2018-09-25T16:20:37
db:CNNVDid:CNNVD-201809-1171date:2018-09-27T00:00:00
db:NVDid:CVE-2018-4353date:2019-04-03T18:29:09.720