Vulnerability CVE-2019-8607: Information

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the disclosure of process memory.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Published: Dec. 18, 2019
Modified: Dec. 23, 2019
Error type identifier: CWE-125

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libwebkitgtk4sisyphus2.24.2-alt12.44.1-alt1ALT-PU-2019-1907-1229994Fixed
libwebkitgtk4p102.24.2-alt12.36.3-alt1ALT-PU-2019-1907-1229994Fixed
libwebkitgtk4p92.24.2-alt12.24.4-alt1.3.p9ALT-PU-2019-1937-1230015Fixed
libwebkitgtk4c10f12.24.2-alt12.36.3-alt1ALT-PU-2019-1907-1229994Fixed
libwebkitgtk4c9f22.24.2-alt12.24.4-alt1.3.c9.1ALT-PU-2019-1937-1230015Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*
      End excliding
      7.12

      cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*
      End excliding
      12.9.5

      cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
      End excliding
      12.1.1

      cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
      End excliding
      12.3

      cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
      End excliding
      12.3

      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
      End excliding
      10.14.5

      cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
      End excliding
      5.2.1

      cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*
      Start including
      10.0
      End excliding
      10.4