First published: Thu Mar 29 2018(Updated: )
PDFKit. An issue existed in the parsing of URLs in PDFs. This issue was addressed through improved input validation.
Credit: Nick Safford Innovia Technology product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.13.4 | |
Apple macOS High Sierra | <10.13.4 | 10.13.4 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4107 is a vulnerability in certain Apple products, specifically macOS before 10.13.4, which involves the "PDFKit" component and allows remote attackers to bypass intended restrictions on visiting URLs within a PDF document.
CVE-2018-4107 affects certain Apple products, including macOS High Sierra before 10.13.4, Sierra, and El Capitan.
CVE-2018-4107 has a severity rating of medium, with a CVSS score of 6.5.
The CWE ID for CVE-2018-4107 is CWE-20.
To fix CVE-2018-4107, update your macOS to version 10.13.4 or later.