CVE-2019-8808
Published on: 12/18/2019 12:00:00 AM UTC
Last Modified on: 12/01/2021 05:04:00 PM UTC
Certain versions of Ipados from Apple contain the following vulnerability:
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVE-2019-8808 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Apple - iOS version < iOS 13.2 and iPadOS 13.2
- Affected Vendor/Software:
Apple - tvOS version < tvOS 13.2
- Affected Vendor/Software:
Apple - watchOS version < watchOS 6.1
- Affected Vendor/Software:
Apple - Safari version < Safari 13.0.3
- Affected Vendor/Software:
Apple - iTunes for Windows version < iTunes for Windows 12.10.2
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
About the security content of watchOS 6.1 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iOS 13.2 and iPadOS 13.2 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
WebkitGTK+: Multiple vulnerabilities (GLSA 202003-22) — Gentoo security | security.gentoo.org text/html |
![]() |
About the security content of tvOS 13.2 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of Safari 13.0.3 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iTunes 12.10.2 for Windows - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
Related QID Numbers
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377553 Alibaba Cloud Linux Security Update for webkitgtk4 (ALINUX2-SA-2020:0147)
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940362 AlmaLinux Security Update for GNOME (ALSA-2020:4451)
- 960761 Rocky Linux Security Update for GNOME (RLSA-2020:4451)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Application | Apple | Itunes | All | All | All | All |
Application | Apple | Itunes | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|