Vulnerability CVE-2019-8746


Published: 2020-10-27

Description:
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

See advisories in our WLB2 database:
Topic
Author
Date
Low
iMessage NSSharedKeyDictionary Decode Out-Of-Bounds Read
saelo
12.11.2019

Type:

CWE-125

(Out-of-bounds Read)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Apple -> Icloud 
Apple -> Itunes 
Apple -> Iphone os 
Apple -> Mac os x 
Apple -> TVOS 
Apple -> Watchos 

 References:
https://support.apple.com/en-us/HT210604
https://support.apple.com/en-us/HT210606
https://support.apple.com/en-us/HT210607
https://support.apple.com/en-us/HT210634
https://support.apple.com/en-us/HT210635
https://support.apple.com/en-us/HT210636
https://support.apple.com/en-us/HT210637
https://support.apple.com/en-us/HT210722

Copyright 2024, cxsecurity.com

 

Back to Top