First published: Thu Mar 29 2018(Updated: )
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
Credit: found by OSS-Fuzz product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 | |
tvOS | <11.3 | 11.3 |
Apple Mobile Safari | <11.1 | 11.1 |
Apple Mobile Safari | <11.1 | |
iOS | <11.3 | |
tvOS | <11.3 | |
Apple iOS, iPadOS, and watchOS | <4.3 | |
All of | ||
Any of | ||
Apple iCloud for Windows | <7.4 | |
Apple iTunes for Windows | <12.7.4 | |
Microsoft Windows | ||
Ubuntu Linux | =18.04 | |
WebKitGTK+ | <2.22.0 | |
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
Apple iOS, iPadOS, and watchOS | <4.3 | 4.3 |
Apple iCloud | <7.4 | 7.4 |
iStyle @cosme iPhone OS | <11.3 | |
Apple iCloud for Windows | <7.4 | |
Apple iTunes for Windows | <12.7.4 | |
Microsoft Windows | ||
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4213 is a vulnerability that allows attackers to cause an ASSERT failure in certain Apple software versions.
The severity of CVE-2018-4213 is high, with a CVSS score of 8.8.
CVE-2018-4213 affects iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3.
To fix CVE-2018-4213, update to the patched versions of the affected software: iOS 11.3 or later, Safari 11.1 or later, iCloud for Windows 7.4 or later, tvOS 11.3 or later, watchOS 4.3 or later.
More information on CVE-2018-4213 can be found at the following references: [CVE-2018-4213](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4213), [Openwall](https://www.openwall.com/lists/oss-security/2018/09/29/1), [WebKitGTK](https://webkitgtk.org/security/WSA-2018-0007.html).