First published: Thu Mar 29 2018(Updated: )
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted string.
Credit: Robin Leroy Google Switzerland GmbHRobin Leroy Google Switzerland GmbHRobin Leroy Google Switzerland GmbHRobin Leroy Google Switzerland GmbH product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <11.3 | 11.3 |
Apple iOS | <11.3 | 11.3 |
Apple iPhone OS | <11.3 | |
Apple Mac OS X | <10.13.4 | |
Apple tvOS | <11.3 | |
Apple watchOS | <4.3 | |
Apple watchOS | <4.3 | 4.3 |
Apple macOS High Sierra | <10.13.4 | 10.13.4 |
Apple Sierra | ||
Apple El Capitan |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4142 is a denial of service vulnerability in CoreText component of certain Apple products.
iOS before 11.3, macOS before 10.13.4, tvOS before 11.3, and watchOS before 4.3 are affected by CVE-2018-4142.
CVE-2018-4142 allows remote attackers to cause a denial of service by crashing the application.
CVE-2018-4142 has a severity rating of high (7.5).
To fix CVE-2018-4142, update your Apple product to the latest version available (iOS 11.3 or later, macOS 10.13.4 or later, tvOS 11.3 or later, watchOS 4.3 or later).