Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple releases iOS 10.2.5, MacOS High Sierra 10.13.3, Apple Watch 4.2.2, tvOS 11.2.5
MacDailyNews ^ | January 23, 2018

Posted on 01/23/2018 7:22:26 PM PST by Swordmaker

Apple releases iOS 11.2.5
Tuesday, January 23, 2018 · 1:17 pm

Apple today released iOS 11.2.5 which includes support for HomePod and introduces the ability for Siri to read the news (US, UK and Australia only). This update also includes bug fixes and improvements. HomePod support

Siri News

Other improvements and fixes

For information on the security content of Apple software updates, please visit this website: https://support.apple.com/kb/HT201222” https://support.apple.com/kb/HT201222

————————————————————————————

Apple releases macOS High Sierra 10.13.3
Tuesday, January 23, 2018 · 2:01 pm

Apple today released macOS High Sierra 10.13.3 Update which is recommended for all macOS High Sierra users.

The macOS High Sierra 10.13.3 Update improves the stability and security of your Mac and is recommended for all users.

This update:

See Apple Security Updates for detailed information about the security content of this update

———————————————————————

Apple releases watchOS 4.2.2
Tuesday, January 23, 2018 · 2:24 pm

Apple today released watchOS 4.2.2 which addresses the following security issues:
Audio
Available for: All Apple Watch models
Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
CVE-2018-4094: Mingi Cho, MinSik Shin, Seoyoung Kim, Yeongho Lee and Taekyoung Kwon of the Information Security Lab, Yonsei University

Core Bluetooth
Available for: All Apple Watch models
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
CVE-2018-4087: Rani Idan (@raniXCH) of Zimperium zLabs Team
CVE-2018-4095: Rani Idan (@raniXCH) of Zimperium zLabs Team

Kernel
Available for: All Apple Watch models
Impact: An application may be able to read restricted memory Description: A memory initialization issue was addressed through improved memory handling.
CVE-2018-4090: Jann Horn of Google Project Zero

Kernel
Available for: All Apple Watch models
Impact: An application may be able to read restricted memory Description: A race condition was addressed through improved locking. CVE-2018-4092: an anonymous researcher

Kernel
Available for: All Apple Watch models
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
CVE-2018-4082: Russ Cox of Google

Kernel
Available for: All Apple Watch models
Impact: An application may be able to read restricted memory
Description: A validation issue was addressed with improved input sanitization.
CVE-2018-4093: Jann Horn of Google Project Zero

LinkPresentation
Available for: All Apple Watch models
Impact: Processing a maliciously crafted text message may lead to application denial of service
Description: A resource exhaustion issue was addressed through improved input validation.
CVE-2018-4100: Abraham Masri (@cheesecakeufo)

QuartzCore
Available for: All Apple Watch models
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue existed in the processing of web content. This issue was addressed through improved input validation.
CVE-2018-4085: Ret2 Systems Inc. working with Trend Micro’s Zero Day Initiative

Security
Available for: All Apple Watch models
Impact: A certificate may have name constraints applied incorrectly Description: A certificate evaluation issue existed in the handling of name constraints. This issue was addressed through improved trust evaluation of certificates.
CVE-2018-4086: Ian Haken of Netflix

WebKit
Available for: All Apple Watch models
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
CVE-2018-4088: Jeonghoon Shin of Theori
CVE-2018-4096: found by OSS-Fuzz

—————————————————————————

Apple releases tvOS 11.2.5
Tuesday, January 23, 2018 · 2:28 pm

Apple today released tvOS 11.2.5 which addresses the following security issues:
Audio
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
CVE-2018-4094: Mingi Cho, MinSik Shin, Seoyoung Kim, Yeongho Lee and Taekyoung Kwon of the Information Security Lab, Yonsei University

Core Bluetooth
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
CVE-2018-4087: Rani Idan (@raniXCH) of Zimperium zLabs Team
CVE-2018-4095: Rani Idan (@raniXCH) of Zimperium zLabs Team

Kernel
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An application may be able to read restricted memory Description: A memory initialization issue was addressed through improved memory handling.
CVE-2018-4090: Jann Horn of Google Project Zero

Kernel
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An application may be able to read restricted memory
Description: A race condition was addressed through improved locking. CVE-2018-4092: an anonymous researcher

Kernel
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved input validation.
CVE-2018-4082: Russ Cox of Google

Kernel
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization.
CVE-2018-4093: Jann Horn of Google Project Zero

QuartzCore
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue existed in the processing of web content. This issue was addressed through improved input validation.
CVE-2018-4085: Ret2 Systems Inc. working with Trend Micro’s Zero Day Initiative

Security
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: A certificate may have name constraints applied incorrectly Description: A certificate evaluation issue existed in the handling of name constraints. This issue was addressed through improved trust evaluation of certificates.
CVE-2018-4086: Ian Haken of NetflixWebKit
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
CVE-2018-4088: Jeonghoon Shin of Theori
CVE-2018-4089: Ivan Fratric of Google Project Zero
CVE-2018-4096: found by OSS-Fuzz


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: applepinglist; meltdown; spectre

1 posted on 01/23/2018 7:22:27 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; 5thGenTexan; AbolishCSEU; Abundy; Action-America; acoulterfan; AFreeBird; ...
Apple updates iOS 11.2.5, macOS High Sierra 10.13. 3, Watch OS 4.2.2, and tvOS 11.2.5. . . And apparently some updates for older devices for MeltDown and Spectre available. — PING!


Apple updates iOS 11.2.5, macOS High Sierra 10.13. 3
Watch OS 4.2.2, and tvOS 11.2.5
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

2 posted on 01/23/2018 7:27:57 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

I’ll be ordering a HomePod this Friday. Looking forward to it.


3 posted on 01/23/2018 7:38:49 PM PST by House Atreides (BOYCOTT the NFL, its products and players 100% - PERMANENTLY)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

I might installing all these updates at my office now.


4 posted on 01/23/2018 7:54:06 PM PST by lefty-lie-spy (Stay metal. For the Horde \m/("_")\m/ - via iPhone from Tokyo.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Ping us when it will report twitter, drudgereport, liberty daily, and free republic.


5 posted on 01/23/2018 8:29:15 PM PST by dila813 (Voting for Trump to Punish Trumpets!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

When Rush was talking about this yesterday, I left the kitchen, came back and found that Siri on my iPhone had been activated by his talking and was waiting for me to ask something.


6 posted on 01/23/2018 10:07:06 PM PST by Moonmad27
[ Post Reply | Private Reply | To 2 | View Replies]

To: Moonmad27

I know what you mean. I was listening to Rush one day and Rush said to a caller all you have to do is say “Hay, Siri” and tell her. . .

As soon as Rush said that both my iPhone and my iPad switched to the Siri attention screen. LOL!


7 posted on 01/23/2018 11:07:59 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker; Moonmad27
> ...all you have to do is say “Hay, Siri” ...

And that, Dear FRiends, is why I refuse to enable that voice-activated function. I am perfectly happy to hold a home button down for two seconds if I want to talk to her. :-)

8 posted on 01/24/2018 5:43:08 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker

Hi Sword. Thanks to your posts I turned off imessages until this patch came out. The update hasn’t been sent to my laptop yet and I don’t see it available on Apple either. As soon as it’s installed, I turn messages back on.


9 posted on 01/24/2018 10:10:21 AM PST by The Westerner (Protect the most vulnerable: get the government out of medicine, education and our for)
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson