CVE-2018-4202: Input Validation
Published Jun 1, 2018
·Updated
iBooks. An input validation issue was addressed with improved input validation.
Other sources
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "iBooks" component. It allows man-in-the-middle attackers to spoof a password prompt.
Credit
Jerry Decime
Affected Software
5 affected componentsFixes available
Apple macOS High Sierra<10.13.5
10.13.5
Apple Sierra
Apple El Capitan
Apple iPhone OS<11.4
Apple iOS and macOS<10.13.5
Event History
Jun 8, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4196
- CVE-2018-4253
- CVE-2018-4256
- CVE-2018-4255
- CVE-2018-4254
- CVE-2018-4258
- CVE-2018-4257
- CVE-2018-7584
- CVE-2018-4219
- CVE-2018-5383
- CVE-2018-4171
- CVE-2018-4194
- CVE-2018-4180
- CVE-2018-4181
- CVE-2018-4182
- CVE-2018-4183
- CVE-2018-4478
- CVE-2018-4251
- CVE-2018-4211
- CVE-2018-4229
- CVE-2018-4159
- CVE-2018-4242
- CVE-2018-4202
- CVE-2018-4217
- CVE-2018-4141
- CVE-2018-4228
- CVE-2018-4236
- CVE-2018-4234
- CVE-2018-4249
- CVE-2018-8897
- CVE-2018-4241
- CVE-2018-4243
- CVE-2018-4237
- CVE-2018-4404
- CVE-2018-4227
- CVE-2018-4235
- CVE-2018-4240
- CVE-2018-4230
- CVE-2018-4221
- CVE-2018-4223
- CVE-2018-4224
- CVE-2018-4225
- CVE-2018-4226
- CVE-2018-4184
- CVE-2018-4198
- CVE-2018-4193
Frequently Asked Questions
1
What is CVE-2018-4202?
CVE-2018-4202 is an input validation issue in the iBooks component of certain Apple products.
2
What products are affected by CVE-2018-4202?
iOS versions before 11.4 and macOS versions before 10.13.5 are affected.
3
How does CVE-2018-4202 impact users?
CVE-2018-4202 allows man-in-the-middle attackers to spoof a password prompt in iBooks.
4
What is the severity of CVE-2018-4202?
CVE-2018-4202 has a severity score of 5.9, which is considered medium.
5
Is there a fix for CVE-2018-4202?
Yes, updating to iOS 11.4 or macOS 10.13.5 will address this vulnerability.