First published: Thu Mar 29 2018(Updated: )
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
Credit: found by OSS-Fuzz product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 | |
tvOS | <11.3 | 11.3 |
Apple Mobile Safari | <11.1 | 11.1 |
Apple Mobile Safari | <11.1 | |
iOS | <11.3 | |
tvOS | <11.3 | |
Apple iOS, iPadOS, and watchOS | <4.3 | |
All of | ||
Any of | ||
Apple iCloud for Windows | <7.4 | |
Apple iTunes for Windows | <12.7.4 | |
Microsoft Windows | ||
Ubuntu Linux | =18.04 | |
WebKitGTK+ | <2.22.0 | |
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
Apple iOS, iPadOS, and watchOS | <4.3 | 4.3 |
Apple iCloud | <7.4 | 7.4 |
iStyle @cosme iPhone OS | <11.3 | |
Apple iCloud for Windows | <7.4 | |
Apple iTunes for Windows | <12.7.4 | |
Microsoft Windows | ||
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4209 is a vulnerability in WebKit that can cause an ASSERT failure due to unexpected interaction.
CVE-2018-4209 has a severity score of 8.8, which is considered high.
Affected software includes iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, and iTunes before 12.7.4 for Windows.
To fix CVE-2018-4209 on Ubuntu, update the 'webkit2gtk' package to version 2.22.2-1ubuntu1 or later.
You can find more information about CVE-2018-4209 on the MITRE CVE website, the OSS Security mailing list, and the WebKitGTK security advisory WSA-2018-0007.