First published: Thu Mar 29 2018(Updated: )
Disk Management. An injection issue was addressed through improved input validation.
Credit: Kamatham Chaitanya ShiftLeft Incan anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.13.4 | |
Apple macOS High Sierra | <10.13.4 | 10.13.4 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability identifier for this issue is CVE-2018-4108.
The severity of CVE-2018-4108 is critical with a severity value of 9.8.
macOS versions before 10.13.4 are affected by this vulnerability.
The impact of CVE-2018-4108 is that attackers can trigger truncation of an APFS volume password via an unspecified injection.
Yes, Apple has released a fix for this vulnerability in macOS 10.13.4.