First published: Thu Mar 29 2018(Updated: )
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
Credit: found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <11.1 | 11.1 |
Apple iCloud for Windows | <7.4 | 7.4 |
Apple watchOS | <4.3 | 4.3 |
Apple tvOS | <11.3 | 11.3 |
Apple iOS | <11.3 | 11.3 |
Apple Safari | <11.1 | |
Apple iPhone OS | <11.3 | |
Apple tvOS | <11.3 | |
Apple watchOS | <4.3 | |
Apple iCloud | <7.4 | |
Apple iTunes | <12.7.4 | |
Microsoft Windows | ||
Canonical Ubuntu Linux | =18.04 | |
Webkitgtk Webkitgtk\+ | <2.22.0 | |
All of | ||
Any of | ||
Apple iCloud | <7.4 | |
Apple iTunes | <12.7.4 | |
Microsoft Windows | ||
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4208 is a vulnerability in WebKit that allows for an ASSERT failure due to unexpected interaction.
iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, and iTunes before 12.7.4 for Windows are affected.
The severity of CVE-2018-4208 is rated as high with a severity value of 8.8.
To fix CVE-2018-4208, update to the latest version of the affected software. Links to remediation instructions can be found in the references section.
More information about CVE-2018-4208 can be found at the following references: <br>1. CVE-2018-4208 on MITRE: <a href='https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4208'>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4208</a> <br>2. OSS Security mailing list: <a href='https://www.openwall.com/lists/oss-security/2018/09/29/1'>https://www.openwall.com/lists/oss-security/2018/09/29/1</a> <br>3. WebKitGTK+ Advisory: <a href='https://webkitgtk.org/security/WSA-2018-0007.html'>https://webkitgtk.org/security/WSA-2018-0007.html</a>