Vulnerability Name: | CVE-2019-8745 (CCN-168438) | ||||||||||||
Assigned: | 2019-10-07 | ||||||||||||
Published: | 2019-10-07 | ||||||||||||
Updated: | 2020-08-24 | ||||||||||||
Summary: | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing a maliciously crafted text file may lead to arbitrary code execution. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-8745 Source: XF Type: UNKNOWN apple-icloud-cve20198745-bo(168438) Source: CCN Type: Apple security document HT210635 About the security content of iTunes 12.10.1 for Windows Source: CCN Type: Apple security document HT210636 About the security content of iCloud for Windows 10.7 Source: CCN Type: Apple security document HT210637 About the security content of iCloud for Windows 7.14 Source: MISC Type: Vendor Advisory https://support.apple.com/HT210634 Source: MISC Type: Vendor Advisory https://support.apple.com/HT210635 Source: MISC Type: Vendor Advisory https://support.apple.com/HT210636 Source: MISC Type: Vendor Advisory https://support.apple.com/HT210637 Source: CONFIRM Type: UNKNOWN https://support.apple.com/kb/HT210722 Source: CCN Type: ZDI-19-863 Apple macOS CFFromShiftJISLen Out-Of-Bounds Read Remote Code Execution Source: CCN Type: ZDI-19-863 Apple macOS CFFromShiftJISLen Out-Of-Bounds Read Remote Code Execution | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Vulnerability Name: | CVE-2019-8745 (CCN-168541) | ||||||||||||
Assigned: | 2019-10-07 | ||||||||||||
Published: | 2019-10-07 | ||||||||||||
Updated: | 2019-10-07 | ||||||||||||
Summary: | Apple macOS Catalina is vulnerable to a buffer overflow, caused by improper bounds checking by the UIFoundation component. By persuading a victim to open a specially crafted text file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-8745 Source: XF Type: UNKNOWN apple-macos-cve20198745-bo(168541) Source: CCN Type: Apple security document HT210634 About the security content of macOS Catalina 10.15 Source: CCN Type: ZDI-19-863 Apple macOS CFFromShiftJISLen Out-Of-Bounds Read Remote Code Execution | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||
BACK |