CVE-2018-4106: Command Injection
Terminal. A command injection issue existed in the handling of Bracketed Paste Mode. This issue was addressed through improved validation of special characters.
Other sources
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands within pasted content.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4170
- CVE-2018-4105
- CVE-2018-4112
- CVE-2018-4166
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2017-13890
- CVE-2017-8816
- CVE-2018-4176
- CVE-2018-4108
- CVE-2017-13080
- CVE-2018-4167
- CVE-2018-4151
- CVE-2018-4132
- CVE-2018-4135
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4136
- CVE-2018-4160
- CVE-2018-4185
- CVE-2018-4139
- CVE-2018-4175
- CVE-2017-15412
- CVE-2018-4187
- CVE-2018-4179
- CVE-2018-4111
- CVE-2018-4174
- CVE-2018-4152
- CVE-2017-7151
- CVE-2018-4138
- CVE-2018-4107
- CVE-2018-4156
- CVE-2018-4157
- CVE-2018-4298
- CVE-2018-4144
- CVE-2017-13911
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4115
- CVE-2018-4106
- CVE-2018-4131
Frequently Asked Questions
What is CVE-2018-4106?
CVE-2018-4106 is a command injection vulnerability in the Bracketed Paste Mode of the Terminal component in macOS before 10.13.4.
What is the severity of CVE-2018-4106?
CVE-2018-4106 has a severity rating of 8.8, which is considered high.
Which versions of macOS are affected by CVE-2018-4106?
macOS before 10.13.4 (High Sierra) is affected by CVE-2018-4106.
How can user-assisted attackers exploit CVE-2018-4106?
User-assisted attackers can inject arbitrary commands within pasted content using the Bracketed Paste Mode.
Are there any references or sources for CVE-2018-4106?
Yes, you can find more information on CVE-2018-4106 from the following sources: [SecurityFocus](http://www.securityfocus.com/bid/103582), [SecurityTracker](http://www.securitytracker.com/id/1040608), and [Apple Support](https://support.apple.com/HT208692).