CVE-2018-4175: Input Validation
Published Mar 29, 2018
·Updated
LaunchServices. A logic issue was addressed with improved validation.
Other sources
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows attackers to bypass the code-signing protection mechanism via a crafted app.
Credit
Theodor Ragnar Gislason(Syndis)
Affected Software
4 affected componentsFixes available
Apple macOS High Sierra<10.13.4
10.13.4
Apple Sierra
Apple El Capitan
Apple iOS and macOS<10.13.4
Event History
Apr 3, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4170
- CVE-2018-4105
- CVE-2018-4112
- CVE-2018-4166
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2017-13890
- CVE-2017-8816
- CVE-2018-4176
- CVE-2018-4108
- CVE-2017-13080
- CVE-2018-4167
- CVE-2018-4151
- CVE-2018-4132
- CVE-2018-4135
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4136
- CVE-2018-4160
- CVE-2018-4185
- CVE-2018-4139
- CVE-2018-4175
- CVE-2017-15412
- CVE-2018-4187
- CVE-2018-4179
- CVE-2018-4111
- CVE-2018-4174
- CVE-2018-4152
- CVE-2017-7151
- CVE-2018-4138
- CVE-2018-4107
- CVE-2018-4156
- CVE-2018-4157
- CVE-2018-4298
- CVE-2018-4144
- CVE-2017-13911
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4115
- CVE-2018-4106
- CVE-2018-4131
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-4175.
2
What products are affected by this vulnerability?
macOS High Sierra before version 10.13.4, Sierra, and El Capitan are affected by this vulnerability.
3
What is the severity of CVE-2018-4175?
The severity of CVE-2018-4175 is high with a CVSS score of 7.8.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by bypassing the code-signing protection mechanism via a crafted app.
5
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is available in macOS version 10.13.4 and above.