WebKit Multiple Security Vulnerabilities
BID:106691
CVE-2019-6212 | CVE-2019-6215 | CVE-2019-6229 | CVE-2019-6233 | CVE-2019-6234 |Info
WebKit Multiple Security Vulnerabilities
| Bugtraq ID: | 106691 |
| Class: | Unknown |
| CVE: |
CVE-2019-6212 CVE-2019-6215 CVE-2019-6229 CVE-2019-6233 CVE-2019-6234 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2019 12:00AM |
| Updated: | Jan 22 2019 12:00AM |
| Credit: | Anonymous researcher, Lokihardt of Google Project Zero, Ryan Pickren, G. Geshev from MWR Labs working with Trend Micro's Zero Day Initiative. |
| Vulnerable: |
WebKit Open Source Project WebKit 0 Apple tvOS 12.1.1 Apple tvOS 11.4.1 Apple tvOS 11.2.6 Apple tvOS 11.2.5 Apple tvOS 10.1.1 Apple tvOS 10.0.1 Apple tvOS 9.2.2 Apple tvOS 9.2.1 Apple tvOS 9.1.1 Apple tvOS 9.2 Apple tvOS 9.1 Apple tvOS 9.0 Apple tvOS 12 Apple tvOS 11.4 Apple tvOS 11.2.1 Apple tvOS 11.2 Apple tvOS 11.1 Apple tvOS 11 Apple tvOS 10.2.2 Apple tvOS 10.2.1 Apple tvOS 10.2 Apple tvOS 10.1 Apple tvOS 10 Apple tvOS 0 Apple Safari 11.1.2 Apple Safari 11.1.1 Apple Safari 11.0.3 Apple Safari 10.1.2 Apple Safari 10.0.1 Apple Safari 9.1.3 Apple Safari 9.1.2 Apple Safari 9.1.1 Apple Safari 9.0.3 Apple Safari 9.0.2 Apple Safari 9.0.1 Apple Safari 8.0.8 Apple Safari 8.0.6 Apple Safari 8.0.5 Apple Safari 8.0.4 Apple Safari 8.0.1 Apple Safari 7.1.8 Apple Safari 7.1.6 Apple Safari 7.1.5 Apple Safari 7.1.4 Apple Safari 7.1.1 Apple Safari 7.1 Apple Safari 7.0.6 Apple Safari 7.0.3 Apple Safari 7.0.1 Apple Safari 6.2.8 Apple Safari 6.2.6 Apple Safari 6.2.5 Apple Safari 6.2.4 Apple Safari 6.2.1 Apple Safari 6.1.6 Apple Safari 6.1.3 Apple Safari 6.1.1 Apple Safari 6.0.5 Apple Safari 6.0.4 Apple Safari 6.0.3 Apple Safari 6.0.2 Apple Safari 6.0.1 Apple Safari 5.1.10 Apple Safari 5.1.6 Apple Safari 5.1.5 Apple Safari 5.0.6 Apple Safari 4.0.5 Apple Safari 4.0.4 Apple Safari 4.0.3 Apple Safari 4.0.1 Apple Safari 3.2.3 Apple Safari 3.1.2 Apple Safari 3.1.1 Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.2 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari 9.1 Apple Safari 9 Apple Safari 8.0.7 Apple Safari 8.0.3 Apple Safari 8.0.2 Apple Safari 8.0 Apple Safari 7.1.7 Apple Safari 7.1.3 Apple Safari 7.1.2 Apple Safari 7.1 Apple Safari 7.0.5 Apple Safari 7.0.4 Apple Safari 7.0.2 Apple Safari 6.2.7 Apple Safari 6.2.3 Apple Safari 6.2.2 Apple Safari 6.2 Apple Safari 6.1.5 Apple Safari 6.1.4 Apple Safari 6.1.2 Apple Safari 6.1 Apple Safari 6.0 Apple Safari 5.1.7 Apple Safari 5.1.4 Apple Safari 5.1.3 Apple Safari 5.1.2 Apple Safari 5.1.1 Apple Safari 5.1 Apple Safari 5.0.5 Apple Safari 5.0.4 Apple Safari 5.0.3 Apple Safari 5.0.2 Apple Safari 5.0.1 Apple Safari 5.0 Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Apple Safari 4 Apple Safari 3.2 Apple Safari 3.1 Apple Safari 3 Apple Safari 12.0.2 Apple Safari 12 Apple Safari 11.1 Apple Safari 11.0.2 Apple Safari 11 Apple Safari 10.1.1 Apple Safari 10.1 Apple Safari 10.0.3 Apple Safari 10.0.2 Apple Safari 10 Apple Safari 0 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 5 0 Apple iOS 4 0 Apple iOS 3 0 Apple iOS 12.1.1 Apple iOS 12.0.1 Apple iOS 11.4.1 Apple iOS 10.2.1 Apple iOS 10.0.1 Apple iOS 9.3.4 Apple iOS 9.3.3 Apple iOS 9.3.2 Apple iOS 9.3.1 Apple iOS 9.2.1 Apple iOS 9.0.2 Apple iOS 9.0.1 Apple iOS 8.4.1 Apple iOS 7.2 Apple iOS 7.0.6 Apple iOS 7.0.5 Apple iOS 7.0.3 Apple iOS 7.0.2 Apple iOS 7.0.1 Apple iOS 6.3.1 Apple iOS 6.1.6 Apple iOS 6.1.4 Apple iOS 6.1.3 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 9.3.5 Apple iOS 9.3 Apple iOS 9.2 Apple iOS 9.1 Apple iOS 9 Apple iOS 8.4 Apple iOS 8.3 Apple iOS 8.2 Apple iOS 8.1.3 Apple iOS 8.1.2 Apple iOS 8.1.1 Apple iOS 8.1 Apple iOS 8 Apple iOS 7.1.2 Apple iOS 7.1.1 Apple iOS 7.1 Apple iOS 7.0.4 Apple iOS 7 Apple iOS 6.1 Apple iOS 6.0.2 Apple iOS 6.0.1 Apple iOS 6 Apple iOS 5.1.1 Apple iOS 5.1 Apple iOS 5.0.1 Apple iOS 5 Apple iOS 4.3.5 Apple iOS 4.3.4 Apple iOS 4.3.3 Apple iOS 4.3.2 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.9 Apple iOS 4.2.8 Apple iOS 4.2.7 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2.10 Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.1 Apple iOS 3.0 Apple iOS 2.1 Apple iOS 2.0 Apple iOS 12.1 Apple iOS 12 Apple iOS 11.4 Apple iOS 11.3.1 Apple iOS 11.3 Apple iOS 11.2.6 Apple iOS 11.2.5 Apple iOS 11.2.2 Apple iOS 11.2.1 Apple iOS 11.2 Apple iOS 11.1 Apple iOS 11 Apple iOS 10.3.3 Apple iOS 10.3.2 Apple iOS 10.3.1 Apple iOS 10.3 Apple iOS 10.2 Apple iOS 10.1 Apple iOS 10 Apple iOS 0 Apple iCloud 6.1.1 Apple iCloud 7.9 Apple iCloud 7.6 Apple iCloud 7.5 Apple iCloud 7.4 Apple iCloud 7.3 Apple iCloud 7.2 Apple iCloud 7.0 Apple iCloud 6.2.2 Apple iCloud 6.2.1 Apple iCloud 6.2 Apple iCloud 6.1 Apple iCloud 6.0.1 Apple iCloud 6.0 Apple iCloud 0 |
| Not Vulnerable: |
Apple tvOS 12.1.2 Apple Safari 12.0.3 Apple iOS 12.1.3 Apple iCloud 7.10 |
Discussion
WebKit Multiple Security Vulnerabilities
WebKit is prone to the following multiple security vulnerabilities:
1. Multiple remote code-execution vulnerabilities
2. A cross-site scripting vulnerability
3. Multiple memory corruption vulnerabilities
Attackers can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or execute arbitrary code and perform unauthorized actions; Failed exploit attempts will result in denial-of-service conditions.
WebKit is prone to the following multiple security vulnerabilities:
1. Multiple remote code-execution vulnerabilities
2. A cross-site scripting vulnerability
3. Multiple memory corruption vulnerabilities
Attackers can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site or execute arbitrary code and perform unauthorized actions; Failed exploit attempts will result in denial-of-service conditions.
Exploit / POC
WebKit Multiple Security Vulnerabilities
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
WebKit Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WebKit Multiple Security Vulnerabilities
References:
References:
- About the security content of iCloud for Windows 7.10 (Apple)
- About the security content of iOS 12.1.3 (Apple)
- About the security content of iTunes 12.9.3 for Windows (Apple)
- About the security content of Safari 12.0.3 (Apple)
- About the security content of tvOS 12.1.2 (Apple)
- Apple iOS Homepage (Apple)
- Apple Safari Homepage (Apple)
- Apple tvOS - Homepage (Apple)
- iCloud Homepage (Apple)
- Webkit Homepage (WebKit)
- APPLE-SA-2019-1-24-1 iTunes 12.9.3 for Windows (Apple)