CVE-2018-4355
published 2019-04-03CVE-2018-4355: A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
PriorityP420medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.20%
41.6th percentile
A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 12.0 | 12.0 |
| apple | mac_os_x | < 10.14 | 10.14 |
| apple | macos_mojave | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Apple
CVE-2018-4355: macOS Mojave 10.14
vendor_apple·2018-09-24·CVSS 5.5
CVE-2018-4355 [MEDIUM] CVE-2018-4355: macOS Mojave 10.14
Apple Security Update: About the security content of macOS Mojave 10.14
Product: macOS Mojave
Version: 10.14
CVE: CVE-2018-4355
Component: Hypervisor
Impact: Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis
Description: An information disclosure issue was addressed by flushing the L1 data cache at the virtual machine entry.
Apple
CVE-2018-4355: iOS 12
vendor_apple·2018-09-17·CVSS 5.5
CVE-2018-4355 [MEDIUM] CVE-2018-4355: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4355
Component: Heimdal
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
GHSA
GHSA-7jfp-hm69-m24f: A configuration issue was addressed with additional restrictions
ghsa_unreviewed·2022-05-14
CVE-2018-4355 [MEDIUM] CWE-200 GHSA-7jfp-hm69-m24f: A configuration issue was addressed with additional restrictions
A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-03
Published