CVE-2018-4111: Medium severity macos high sierra vulnerability
Mail. An issue existed in the handling of S/MIME HTML e-mail. This issue was addressed by not loading remote resources on S/MIME encrypted messages by default if the message has an invalid or missing S/MIME signature.
Other sources
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Mail" component. It allows man-in-the-middle attackers to read S/MIME encrypted message content by sending HTML e-mail that references remote resources but lacks a valid S/MIME signature.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4170
- CVE-2018-4105
- CVE-2018-4112
- CVE-2018-4166
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2017-13890
- CVE-2017-8816
- CVE-2018-4176
- CVE-2018-4108
- CVE-2017-13080
- CVE-2018-4167
- CVE-2018-4151
- CVE-2018-4132
- CVE-2018-4135
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4136
- CVE-2018-4160
- CVE-2018-4185
- CVE-2018-4139
- CVE-2018-4175
- CVE-2017-15412
- CVE-2018-4187
- CVE-2018-4179
- CVE-2018-4111
- CVE-2018-4174
- CVE-2018-4152
- CVE-2017-7151
- CVE-2018-4138
- CVE-2018-4107
- CVE-2018-4156
- CVE-2018-4157
- CVE-2018-4298
- CVE-2018-4144
- CVE-2017-13911
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4115
- CVE-2018-4106
- CVE-2018-4131
Frequently Asked Questions
What is CVE-2018-4111?
CVE-2018-4111 is a vulnerability that exists in the handling of S/MIME HTML e-mail in certain Apple products, specifically macOS before version 10.13.4.
How does CVE-2018-4111 affect Apple products?
CVE-2018-4111 allows man-in-the-middle attackers to read S/MIME encrypted message content in the 'Mail' component of affected Apple products.
Which versions of macOS are affected by CVE-2018-4111?
macOS versions before 10.13.4 are affected by CVE-2018-4111.
What is the severity of CVE-2018-4111?
The severity of CVE-2018-4111 is medium, with a CVSSv3 base score of 5.9.
How can CVE-2018-4111 be mitigated?
To mitigate CVE-2018-4111, update macOS to version 10.13.4 or later.