First published: Tue Sep 12 2017(Updated: )
libxml2. A null pointer dereference was addressed with improved validation.
Credit: Gustavo Grieco Gustavo Grieco Gustavo Grieco Gustavo Grieco Gustavo Grieco product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.0 | 7.0 |
Apple iTunes for Windows | <12.7 | 12.7 |
Apple macOS High Sierra | <10.13 | 10.13 |
Apple watchOS | <4 | 4 |
Apple iOS | <11 | 11 |
Apple Icloud Windows | <=7.0 | |
Apple Itunes Windows | <12.7 | |
Apple iPhone OS | <11 | |
Apple Mac OS X | <10.13 | |
Apple watchOS | <4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4302 is a vulnerability in libxml2 that can lead to an unexpected application termination or arbitrary code execution when processing maliciously crafted XML.
CVE-2018-4302 has a severity rating of 7.8, which is considered high.
CVE-2018-4302 affects macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, and iTunes 12.7 for Windows.
To fix CVE-2018-4302, update to macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, or iTunes 12.7 for Windows.
More information about CVE-2018-4302 can be found in the Apple support articles: [here](https://support.apple.com/en-us/HT208112), [here](https://support.apple.com/en-us/HT208115), and [here](https://support.apple.com/en-us/HT208141).