A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS High Sierra 10.13.6, macOS Mojave 10.14.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
WebKit. A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
Accounts. A privacy issue in the handling of Open Directory records was addressed with improved indexing.
AMD. An information disclosure issue was addressed by removing the vulnerable code.
APFS. A memory corruption issue was addressed with improved memory handling.
ATS. A type confusion issue was addressed with improved memory handling.
CUPS. A null pointer dereference was addressed with improved validation.
DesktopServices. A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation.
IOGraphics. An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation.
An information leakage flaw is found in the way Linux kernel saves and restores Floating Point Unit(FPU) state during task switch. There are two ways, one is to save & restore FPU state during task context switch. And second is to defer FPU state save & restore until an FP instruction is invoked by the current task. First is called as "Eager FPU Restore" and second is known as "Lazy FPU Restore" scheme.
Linux kernel which follows the "Lazy FPU Restore" scheme is vulnerable to the FPU state information leakage issue. An unprivileged local attacker could use this flaw to read FPU state bits by conducting targeted cache side-channel attacks, similar to Meltdown attack disclosed earlier this year.
Upstream fix: ------------- -> https://git.kernel.org/linus//58122bf1d856a4ea9581d62a07c557d997d46a19
References: ----------- -> http://www.openwall.com/lists/oss-security/2018/06/13/7
EFI. A validation issue was addressed with improved logic.
CUPS. An issue existed in CUPS. This issue was addressed with improved access restrictions.
CUPS. An issue existed in CUPS. This issue was addressed with improved access restrictions.
CUPS. An access issue was addressed with additional sandbox restrictions.
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Hypervisor" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
libxpc. A logic issue was addressed with improved validation.
IOHIDFamily. A memory corruption issue was addressed with improved memory handling.