ID

VAR-201806-1464


CVE

CVE-2018-4220


TITLE

Apple Swift of Ubuntu for Swift Component vulnerable to arbitrary code execution in privileged context

Trust: 0.8

sources: JVNDB: JVNDB-2018-005529

DESCRIPTION

An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu" component. It allows attackers to execute arbitrary code in a privileged context because write and execute permissions are enabled during library loading. Apple Swift is prone to an arbitrary code-execution vulnerability. Failed attempts will likely cause a denial-of-service condition. Apple Swift is a programming language for macOS, iOS, watchOS and tvOS developed by Apple. This issue was addressed with improved permissions. Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 and the Swift announcements section on the forum: https://forums.swift.org/c/general-announce This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQJdBAEBCgBHFiEEcuX4rtoRe4X62yWlg6PvjDRstEYFAlrsmUcpHHByb2R1Y3Qt c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQg6PvjDRstEbkbA// TuLWltNrBXakVq4NY1wBZ0P+/SYUlw312FHtWrtDcAKNykyfED9bA8AnG0Ux3d1g MdJqT9KkRLXOSunWgiXG8IpWH9KCApeWDV/AE4p6isgOzE4orx02QeHzu9zc7RN6 jBVlfJaGCpTzVuFJRiEimyupjbd5db33N8raRmLxMUKTn0jVjG6ARNS7G+rpUygE 4Dy/lwP05tLWffK1O+w0oihfGsxEl1xiNAcErHTk6Fb/ZVHiITXsuOw9E775dRsM 5fkuyVU6uyhzVNWXkJ9AhOlld7t6gBFNCADMsi+jSqT6EYCHKODBXrar0CfafrsP edAvUE6PopD2i5ee7msdB+WxTLf1J/WPqT4kyD9kD4SwPeE6eN8evTqubNsOF+jc cwhsgFuH34AvsoCea5i5v9mwLpjWodgq6OyMkF0Ee3shVx8HRo2Gm/sjj/THJq/G 76Wkfb2bOcVJ3ncDAHAHO3tWfrqZYD9+Eg5hQLwyRDpBKTBzl9R5yXQZFa0naLdC 1iEzXtom+IeXn9jYqE79qOUkBSMzZQ95j98CklKGfKMz8UtfOzM2+mmwCSx5CAwC H92XBJ7wMyg6EEgByPX89Y4oyg9Ng+reTtAQD2TC9rygEKh5LMJxlhCM+CLDWEqC ys0NCk7M9izqbAZ4zsf+D+Ml/4h71iDBae92JURjhas= =sqwr -----END PGP SIGNATURE-----

Trust: 2.07

sources: NVD: CVE-2018-4220 // JVNDB: JVNDB-2018-005529 // BID: 104085 // VULHUB: VHN-134251 // PACKETSTORM: 147506

AFFECTED PRODUCTS

vendor:applemodel:swiftscope:ltversion:4.1.1

Trust: 1.0

vendor:applemodel:swiftscope:ltversion:4.1.1 (ubuntu 14.04)

Trust: 0.8

vendor:ubuntumodel:linuxscope:eqversion:14.04

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:4.0.3

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:3.1.1

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:3.0.2

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:3.0.1

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:3.1

Trust: 0.3

vendor:applemodel:swiftscope:eqversion:3.0

Trust: 0.3

vendor:applemodel:swiftscope:neversion:4.1.1

Trust: 0.3

sources: BID: 104085 // JVNDB: JVNDB-2018-005529 // NVD: CVE-2018-4220

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-4220
value: HIGH

Trust: 1.0

NVD: CVE-2018-4220
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201805-1051
value: HIGH

Trust: 0.6

VULHUB: VHN-134251
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-4220
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-134251
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-4220
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-134251 // JVNDB: JVNDB-2018-005529 // CNNVD: CNNVD-201805-1051 // NVD: CVE-2018-4220

PROBLEMTYPE DATA

problemtype:CWE-732

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-134251 // JVNDB: JVNDB-2018-005529 // NVD: CVE-2018-4220

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-1051

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201805-1051

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005529

PATCH

title:HT208804url:https://support.apple.com/en-us/HT208804

Trust: 0.8

title:HT208804url:https://support.apple.com/ja-jp/HT208804

Trust: 0.8

title:Apple Swift Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=80581

Trust: 0.6

sources: JVNDB: JVNDB-2018-005529 // CNNVD: CNNVD-201805-1051

EXTERNAL IDS

db:NVDid:CVE-2018-4220

Trust: 2.9

db:BIDid:104085

Trust: 2.0

db:JVNid:JVNVU98864649

Trust: 0.8

db:JVNDBid:JVNDB-2018-005529

Trust: 0.8

db:CNNVDid:CNNVD-201805-1051

Trust: 0.7

db:PACKETSTORMid:147506

Trust: 0.2

db:VULHUBid:VHN-134251

Trust: 0.1

sources: VULHUB: VHN-134251 // BID: 104085 // JVNDB: JVNDB-2018-005529 // PACKETSTORM: 147506 // CNNVD: CNNVD-201805-1051 // NVD: CVE-2018-4220

REFERENCES

url:http://www.securityfocus.com/bid/104085

Trust: 1.7

url:https://support.apple.com/ht208804

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-4220

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4220

Trust: 0.8

url:https://jvn.jp/vu/jvnvu98864649/index.html

Trust: 0.8

url:https://www.apple.com/

Trust: 0.3

url:https://swift.org/

Trust: 0.3

url:https://support.apple.com/en-us/ht208804

Trust: 0.3

url:https://lists.apple.com/archives/security-announce/2018/may/msg00000.html

Trust: 0.3

url:https://forums.swift.org/c/general-announce

Trust: 0.1

url:https://support.apple.com/kb/ht201222

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://swift.org/download.

Trust: 0.1

sources: VULHUB: VHN-134251 // BID: 104085 // JVNDB: JVNDB-2018-005529 // PACKETSTORM: 147506 // CNNVD: CNNVD-201805-1051 // NVD: CVE-2018-4220

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 104085

SOURCES

db:VULHUBid:VHN-134251
db:BIDid:104085
db:JVNDBid:JVNDB-2018-005529
db:PACKETSTORMid:147506
db:CNNVDid:CNNVD-201805-1051
db:NVDid:CVE-2018-4220

LAST UPDATE DATE

2024-11-23T19:35:57.835000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-134251date:2019-10-03T00:00:00
db:BIDid:104085date:2018-05-04T00:00:00
db:JVNDBid:JVNDB-2018-005529date:2018-07-20T00:00:00
db:CNNVDid:CNNVD-201805-1051date:2019-10-23T00:00:00
db:NVDid:CVE-2018-4220date:2024-11-21T04:06:59.873

SOURCES RELEASE DATE

db:VULHUBid:VHN-134251date:2018-06-08T00:00:00
db:BIDid:104085date:2018-05-04T00:00:00
db:JVNDBid:JVNDB-2018-005529date:2018-07-20T00:00:00
db:PACKETSTORMid:147506date:2018-05-05T12:12:12
db:CNNVDid:CNNVD-201805-1051date:2018-06-05T00:00:00
db:NVDid:CVE-2018-4220date:2018-06-08T18:29:01.400