what you don't know can hurt you

Apple Security Advisory 2018-9-17-3

Apple Security Advisory 2018-9-17-3
Posted Sep 18, 2018
Authored by Apple | Site apple.com

Apple Security Advisory 2018-9-17-3 - tvOS 12 is now available and addresses interception issues.

tags | advisory
systems | apple
advisories | CVE-2016-1777, CVE-2018-4305, CVE-2018-4313, CVE-2018-4363, CVE-2018-5383
MD5 | d364030cc534c515c923cb61691877bd

Apple Security Advisory 2018-9-17-3

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2018-9-17-3 tvOS 12

tvOS 12 is now available and addresses the following:

Bluetooth
Available for: Apple TV (4th generation)
Impact: An attacker in a privileged network position may be able to
intercept Bluetooth traffic
Description: An input validation issue existed in Bluetooth. This
issue was addressed with improved input validation.
CVE-2018-5383: Lior Neumann and Eli Biham

iTunes Store
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An attacker in a privileged network position may be able to
spoof password prompts in the iTunes Store
Description: An input validation issue was addressed with improved
input validation.
CVE-2018-4305: Jerry Decime

Kernel
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An application may be able to read restricted memory
Description: An input validation issue existed in the kernel. This
issue was addressed with improved input validation.
CVE-2018-4363: Ian Beer of Google Project Zero

Safari
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: A local user may be able to discover websites a user has
visited
Description: A consistency issue existed in the handling of
application snapshots. The issue was addressed with improved handling
of application snapshots.
CVE-2018-4313: 11 anonymous researchers, David Scott,
Enes Mert Ulu of Abdullah MA1/4rAide AzA1/4nenek Anadolu Lisesi -
Ankara/TA1/4rkiye, Mehmet Ferit DaAtan of Van YA1/4zA1/4ncA1/4 YA+-l
University, Metin Altug Karakaya of Kaliptus Medical Organization,
Vinodh Swami of Western Governor's University (WGU)

Security
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An attacker may be able to exploit weaknesses in the RC4
cryptographic algorithm
Description: This issue was addressed by removing RC4.
CVE-2016-1777: Pepi Zawodsky

Installation note:

Apple TV will periodically check for software updates. Alternatively,
you may manually check for software updates by selecting
"Settings -> System -> Software Update -> Update Software."

To check the current version of software, select
"Settings -> General -> About."

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlud5zQACgkQeC9tht7T
K3GiYQ/+ICUWZ9g5pgue1pw5NrMiB3GmCjBMZ2TvFcDI3f5eEoJuEuzHedbjG+z5
0Rsck24qaQ6zWMTXmEH4DMQuWhKjIDSKDekUT4vL8tn4BisQ01QVHbtAmm20iKwV
GNlTkbnsfnSaXqA7IZu4FsAiuUjOenGtesYOX+jIqQ2gMAwyMOGZdJjbwukHlvKN
ukzqWITwewXb6fqDHGkrkmgAaxYf4drt3E6e5kXXa50MxcYMevHkcxTbFdDOfG6S
F9155xwqQtXasKWTpbTYyIJr349hy3Tjz559jSH863w6K7gnFbNquvQCqDMgA8dR
wlHLUqTcZm0p3tE/5m07biLK2agoJEhHZtk/VOYsZMwame+H4HPzn8avzHHqfDPI
phVRxeIiTKgm/rZpDZK18AQhBX3LrPdh4lpgcfNmBXWVRpk1m4CvJmL3CO8jzmNX
hRYyW2zSR3dxsrO4nRL+Jipl6pBEpGiw0t/urQo9Pts4zNQu9b7DAAxqao/kf7xO
JBzlVIWyWWeeX6EqxiBDyeo3HH+E8rT8Zw8XKsJlqmEAdXDoBsYO1VOAIERIpV0j
gxcCH5rZzjDxasKH5wnYFdjI1Z1JQqLFTWSfrig1fSkXcv7v7SbxvkpQN0djy+WB
slnm/cZ9fYL+C8BUMOeXR0GBsY1gKyAVlQ9MejWCodI6QrvqEx4=
=5cmn
-----END PGP SIGNATURE-----



Login or Register to add favorites

File Archive:

August 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    3 Files
  • 2
    Aug 2nd
    2 Files
  • 3
    Aug 3rd
    32 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    0 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close