MEDIUM
A memory initialization issue was addressed with improved memory handling
Published Oct 27, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.29%
Description
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.1.1, watchOS 5.1.2, macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierra, tvOS 12.1.1. A local user may be able to read kernel memory.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<12.1
- Version
-
- Version unspecifiedStatusaffectedConstraints<10.14
- Version unspecifiedStatusaffectedConstraints<12.1
- Version unspecifiedStatusaffectedConstraints<5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (5)
- https://support.apple.com/en-us/HT209340 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT209341 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT209342 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT209343 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT209600 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.apple.com/en-us/HT209340 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT209341 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT209342 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT209343 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT209600 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Oct 27, 2020
Updated Aug 5, 2024
Reserved Jan 2, 2018
Link CVE-2018-4448
CISA Vulnrichment
Updated n/a