CVE-2018-4183: High severity macos high sierra vulnerability
CUPS. An access issue was addressed with additional sandbox restrictions.
Other sources
In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.
— MITRE
The sandbox profile dynamically generated by cupsdCreateProfile() unintentionally allows write access to /etc/cups. This can be used by an attacker that has obtained sandboxed root access to alter /etc/cups/cups-files.conf, leading to unsandboxed root code execution.
References:
https://blog.gdssecurity.com/labs/2018/7/11/cups-local-privilege-escalation-and-sandbox-escapes.html
Upstream patch:
https://github.com/apple/cups/commit/d47f6aec436e0e9df6554436e391471097686ecc
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4196
- CVE-2018-4253
- CVE-2018-4256
- CVE-2018-4255
- CVE-2018-4254
- CVE-2018-4258
- CVE-2018-4257
- CVE-2018-7584
- CVE-2018-4219
- CVE-2018-5383
- CVE-2018-4171
- CVE-2018-4194
- CVE-2018-4180
- CVE-2018-4181
- CVE-2018-4182
- CVE-2018-4183
- CVE-2018-4478
- CVE-2018-4251
- CVE-2018-4211
- CVE-2018-4229
- CVE-2018-4159
- CVE-2018-4242
- CVE-2018-4202
- CVE-2018-4217
- CVE-2018-4141
- CVE-2018-4228
- CVE-2018-4236
- CVE-2018-4234
- CVE-2018-4249
- CVE-2018-8897
- CVE-2018-4241
- CVE-2018-4243
- CVE-2018-4237
- CVE-2018-4404
- CVE-2018-4227
- CVE-2018-4235
- CVE-2018-4240
- CVE-2018-4230
- CVE-2018-4221
- CVE-2018-4223
- CVE-2018-4224
- CVE-2018-4225
- CVE-2018-4226
- CVE-2018-4184
- CVE-2018-4198
- CVE-2018-4193
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2018-4183.
What is the severity of CVE-2018-4183?
The severity of CVE-2018-4183 is high with a severity value of 8.2.
What is the affected software?
The affected software includes Apple macOS High Sierra versions up to 10.13.5, Apple Sierra, and Apple El Capitan.
What was addressed in this issue?
This issue addressed an access issue with additional sandbox restrictions.
How can I fix CVE-2018-4183?
To fix CVE-2018-4183, update your macOS High Sierra to version 10.13.5 or later.