CVE-2018-4139: Buffer Overflow
kext tools. A logic issue existed resulting in memory corruption. This was addressed with improved state management.
Other sources
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4170
- CVE-2018-4105
- CVE-2018-4112
- CVE-2018-4166
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2017-13890
- CVE-2017-8816
- CVE-2018-4176
- CVE-2018-4108
- CVE-2017-13080
- CVE-2018-4167
- CVE-2018-4151
- CVE-2018-4132
- CVE-2018-4135
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4136
- CVE-2018-4160
- CVE-2018-4185
- CVE-2018-4139
- CVE-2018-4175
- CVE-2017-15412
- CVE-2018-4187
- CVE-2018-4179
- CVE-2018-4111
- CVE-2018-4174
- CVE-2018-4152
- CVE-2017-7151
- CVE-2018-4138
- CVE-2018-4107
- CVE-2018-4156
- CVE-2018-4157
- CVE-2018-4298
- CVE-2018-4144
- CVE-2017-13911
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4115
- CVE-2018-4106
- CVE-2018-4131
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-4139.
What is the severity level of CVE-2018-4139?
The severity level of CVE-2018-4139 is critical, with a severity value of 7.8.
Which software versions are affected by CVE-2018-4139?
macOS versions before 10.13.4, including macOS High Sierra, Sierra, and El Capitan, are affected by CVE-2018-4139.
What is the impact of CVE-2018-4139?
CVE-2018-4139 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Where can I find more information about CVE-2018-4139?
More information about CVE-2018-4139 can be found at the following references: [securityfocus](http://www.securityfocus.com/bid/103582), [securitytracker](http://www.securitytracker.com/id/1040608), [Apple Support](https://support.apple.com/HT208692).