CVE-2018-4121
published 2018-04-03CVE-2018-4121: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected…
PriorityP265high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
13.21%
96.0th percentile
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.4 | 7.4 |
| apple | icloud_for_windows | — | — |
| apple | ios | — | — |
| apple | iphone_os | < 11.3 | 11.3 |
| apple | itunes | < 12.7.4 | 12.7.4 |
| apple | itunes_12.7.4_for_windows | — | — |
| apple | safari | < 11.1 | 11.1 |
| apple | safari | — | — |
| apple | tvos | < 11.3 | 11.3 |
| apple | tvos | — | — |
| apple | watchos | < 4.3 | 4.3 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.20.0-2 (bookworm) | webkit2gtk 2.20.0-2 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets WebAssembly binary parsing in WebKit — look for crafted .wasm files delivered via web content, particularly binaries with out-of-order or repeated sections (e.g., duplicate non-Custom sections) ↗
- →The specific overflow triggered is in the function vector — monitor for crashes or memory corruption in WebKit's WebAssembly function vector during .wasm parsing ↗
- →Exploit PoC is delivered as an HTML file paired with a .wasm file — detect suspicious HTML pages loading malformed WebAssembly binaries with repeated or misordered sections ↗
- →Any number of sections can appear multiple times and in any order in the malicious .wasm — a WASM parser/IDS rule should flag binaries where non-Custom sections appear more than once or out of spec order ↗
- ·The validateOrder() logic flaw only bypasses ordering checks when the *previous* section was a Custom section — malicious .wasm files must interleave Custom sections to exploit this ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: memory corruption processing maliciously crafted web content
vendor_redhat·2018-05-07·CVSS 8.8
CVE-2018-4121 [HIGH] CWE-119 webkitgtk: memory corruption processing maliciously crafted web content
webkitgtk: memory corruption processing maliciously crafted web content
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Package: webkitgtk4 (Red Hat Enterprise Linux 8) - Not affected
Apple
CVE-2018-4121: watchOS 4.3
vendor_apple·2018-03-29·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: watchOS 4.3
Apple Security Update: About the security content of watchOS 4.3
Product: watchOS
Version: 4.3
CVE: CVE-2018-4121
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
Apple
CVE-2018-4121: iCloud for Windows 7.4
vendor_apple·2018-03-29·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: iCloud for Windows 7.4
Apple Security Update: About the security content of iCloud for Windows 7.4
Product: iCloud for Windows
Version: 7.4
CVE: CVE-2018-4121
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
Apple
CVE-2018-4121: tvOS 11.3
vendor_apple·2018-03-29·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: tvOS 11.3
Apple Security Update: About the security content of tvOS 11.3
Product: tvOS
Version: 11.3
CVE: CVE-2018-4121
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
Apple
CVE-2018-4121: iOS 11.3
vendor_apple·2018-03-29·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4121
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
Apple
CVE-2018-4121: Safari 11.1
vendor_apple·2018-03-29·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: Safari 11.1
Apple Security Update: About the security content of Safari 11.1
Product: Safari
Version: 11.1
CVE: CVE-2018-4121
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
Apple
CVE-2018-4121: iTunes 12.7.4 for Windows
vendor_apple·2018-03-29·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: iTunes 12.7.4 for Windows
Apple Security Update: About the security content of iTunes 12.7.4 for Windows
Product: iTunes 12.7.4 for Windows
CVE: CVE-2018-4121
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
Debian
CVE-2018-4121: webkit2gtk - An issue was discovered in certain Apple products. iOS before 11.3 is affected. ...
vendor_debian·2018·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: webkit2gtk - An issue was discovered in certain Apple products. iOS before 11.3 is affected. ...
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Scope: local
bookworm: resolved (fixed in 2.20.0-2)
bullseye: resolved (fixed in 2.20.0-2)
forky: resolved (fixed in 2.20.0-2)
sid: resolved (fixed in 2.20.0-2)
trixie: resolved (fixed in 2.20.0-2)
GHSA
GHSA-pg93-h5rr-phmm: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-14
CVE-2018-4121 [HIGH] CWE-119 GHSA-pg93-h5rr-phmm: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Project0
The Problems and Promise of WebAssembly - Project Zero
project_zero·2018-08-01
CVE-2018-4121 The Problems and Promise of WebAssembly - Project Zero
Posted by Natalie Silvanovich, Project Zero
WebAssembly is a format that allows code written in assembly-like instructions to be run from JavaScript. It has recently been implemented in all four major browsers. We reviewed each browser’s WebAssembly implementation and found three vulnerabilities. This blog post gives an overview of the features and attack surface of WebAssembly, as well as the vulnerabilities we found.
##
Building WebAssembly
A number of tools can be used to write WebAssembly code. An important goal of the designers of the format is to be able to compile C and C++ into WebAssembly, and compilers exist to do so. It is likely that other languages will compile into WebAssembly in the future. It is also possible to write WebAssembly in WebAssembly text format which is a d
OSV
CVE-2018-4121: An issue was discovered in certain Apple products
osv·2018-04-03·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
No detection rules found.
Exploit-DB
Ayukov NFTP FTP Client 2.0 - Buffer Overflow
exploitdb·2019-01-02·CVSS 9.8
CVE-2017-15222 [CRITICAL] Ayukov NFTP FTP Client 2.0 - Buffer Overflow
Ayukov NFTP FTP Client 2.0 - Buffer Overflow
---
# Exploit Title: Ayukov NFTP FTP Client 2.0 - Buffer Overflow
# Date: 2018-12-29
# Exploit Author: Uday Mittal
# Vendor Homepage: http://www.ayukov.com/nftp/
# Software Link: ftp://ftp.ayukov.com/pub/src/nftp-1.72.zip
# Version : below 2.0
# Tested on: Microsoft Windows XP SP3
# CVE: CVE-2017-15222
# EIP Location: 4116
# Buffer starts from : 4121
# 0x7e45b310 : jmp esp | {PAGE_EXECUTE_READ} [USER32.dll] ASLR: False, Rebase: False, SafeSEH: True, OS: True, v5.1.2600.5512 (C:\WINDOWS\system32\USER32.dll)
# badchars: '\x00\x0A\x0D\x40'
# Shellcode: msfvenom -p windows/shell_bind_tcp RHOST=192.168.43.72 LPORT=4444 -b '\x00\x0A\x0D' -f python
import socket
IP = '192.168.43.28'
port = 21
buf = ""
buf += "\xbb\x04\x8b\xfc\xf1\xd9\xc4\xd9\x74\
Exploit-DB
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
exploitdb·2018-04-09
CVE-2018-4121 WebKit - WebAssembly Parsing Does not Correctly Check Section Order
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
---
When a WebAssembly binary is parsed in ModuleParser::parse, it is expected to contain certain sections in a certain order, but can also contain custom sections that can appear anywhere in the binary. The ordering check validateOrder() does not adequately check that sections are in the correct order when a binary contains custom sections.
static inline bool validateOrder(Section previous, Section next)
{
if (previous == Section::Custom)
return true;
return static_cast(previous) (next);
}
If the previous section was a custom section, the check always returns true, even if the section is otherwise out of order. This means any number of sections can be parsed from a binary, any number of times in any order. This leads
Bugzilla
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 mingw-webkitgtk3: various flaws [fedora-all]
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 mingw-webkitgtk3: various flaws [fedora-all]
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 mingw-webkitgtk3: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk: various flaws [fedora-all]
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk: various flaws [fedora-all]
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk: various flaws [epel-all]
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk: various flaws [epel-all]
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk4: various flaws [fedora-all]
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk4: various flaws [fedora-all]
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 webkitgtk4: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 mingw-webkitgtk: various flaws [fedora-all]
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 mingw-webkitgtk: various flaws [fedora-all]
CVE-2018-4121 CVE-2018-4200 CVE-2018-4204 mingw-webkitgtk: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-4121 webkitgtk: memory corruption processing maliciously crafted web content
bugzilla·2018-05-11·CVSS 8.8
CVE-2018-4121 [HIGH] CVE-2018-4121 webkitgtk: memory corruption processing maliciously crafted web content
CVE-2018-4121 webkitgtk: memory corruption processing maliciously crafted web content
A flaw was found in WebKitGTK+ before version 2.20.0. A memory corruption issue when processing maliciously crafted web content may lead to arbitrary code execution. processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://webkitgtk.org/security/WSA-2018-0004.html
Discussion:
Created mingw-webkitgtk tracking bugs for this issue:
Affects: fedora-all [bug 1577375]
Created mingw-webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1577380]
Created webkitgtk tracking bugs for this issue:
Affects: epel-all [bug 1577378]
Affects: fedora-all [bug 1577377]
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1577379]
http://www.securitytracker.com/id/1040604https://github.com/mwrlabs/CVE-2018-4121https://security.gentoo.org/glsa/201808-04https://support.apple.com/HT208693https://support.apple.com/HT208694https://support.apple.com/HT208695https://support.apple.com/HT208696https://support.apple.com/HT208697https://support.apple.com/HT208698https://www.exploit-db.com/exploits/44427/http://www.securitytracker.com/id/1040604https://github.com/mwrlabs/CVE-2018-4121https://security.gentoo.org/glsa/201808-04https://support.apple.com/HT208693https://support.apple.com/HT208694https://support.apple.com/HT208695https://support.apple.com/HT208696https://support.apple.com/HT208697https://support.apple.com/HT208698https://www.exploit-db.com/exploits/44427/
2018-04-03
Published