CVE-2018-4138: Infoleak
NVIDIA Graphics Drivers. A validation issue was addressed with improved input sanitization.
Other sources
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4170
- CVE-2018-4105
- CVE-2018-4112
- CVE-2018-4166
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2017-13890
- CVE-2017-8816
- CVE-2018-4176
- CVE-2018-4108
- CVE-2017-13080
- CVE-2018-4167
- CVE-2018-4151
- CVE-2018-4132
- CVE-2018-4135
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4136
- CVE-2018-4160
- CVE-2018-4185
- CVE-2018-4139
- CVE-2018-4175
- CVE-2017-15412
- CVE-2018-4187
- CVE-2018-4179
- CVE-2018-4111
- CVE-2018-4174
- CVE-2018-4152
- CVE-2017-7151
- CVE-2018-4138
- CVE-2018-4107
- CVE-2018-4156
- CVE-2018-4157
- CVE-2018-4298
- CVE-2018-4144
- CVE-2017-13911
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4115
- CVE-2018-4106
- CVE-2018-4131
Frequently Asked Questions
What is the vulnerability CVE-2018-4138 about?
The vulnerability CVE-2018-4138 is a validation issue in NVIDIA Graphics Drivers that allows attackers to bypass memory-read restrictions via a crafted app.
Which Apple products are affected by CVE-2018-4138?
macOS before 10.13.4, macOS High Sierra (up to 10.13.4), Sierra, and El Capitan are affected by CVE-2018-4138.
What is the severity value of CVE-2018-4138?
The severity value of CVE-2018-4138 is 5.5, which is considered medium.
How can an attacker exploit CVE-2018-4138?
An attacker can exploit CVE-2018-4138 by using a crafted app to bypass memory-read restrictions.
Where can I find more information about CVE-2018-4138?
You can find more information about CVE-2018-4138 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/103582), [SecurityTracker](http://www.securitytracker.com/id/1040608), and [Apple support page](https://support.apple.com/HT208692).