ID

VAR-201912-0113


CVE

CVE-2019-8798


TITLE

plural Apple Updates to product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2019-011304

DESCRIPTION

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges. Apple Has released an update for each product.The expected impact depends on each vulnerability, but can be affected as follows: * * information leak * * User impersonation * * Arbitrary code execution * * UI Spoofing * * Insufficient access restrictions * * Service operation interruption (DoS) * * Privilege escalation * * Memory corruption * * Authentication bypass. This vulnerability allows local attackers to disclose sensitive information on affected installations of Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the fseventsd daemon. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute code in the context of the kernel. Apple iOS, etc. are all products of Apple (Apple). Apple iOS is an operating system developed for mobile devices. Apple tvOS is a smart TV operating system. File System Events is one of the file system event reporting components. A security vulnerability exists in the File System Events component of several Apple products. The following products and versions are affected: Apple macOS Catalina prior to 10.15.1; watchOS prior to 6.1; iOS prior to 13.2; iPadOS prior to 13.2; tvOS prior to 13.2. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-10-29-2 macOS Catalina 10.15.1, Security Update 2019-001 Mojave, Security Update 2019-006 High Sierra macOS Catalina 10.15.1, Security Update 2019-001 Mojave, Security Update 2019-006 High Sierra are now available and address the following: Accounts Available for: macOS Catalina 10.15 Impact: A remote attacker may be able to leak memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2019-8787: Steffen Klee of Secure Mobile Networking Lab at Technische Universität Darmstadt App Store Available for: macOS Catalina 10.15 Impact: A local attacker may be able to login to the account of a previously logged in user without valid credentials. CVE-2019-8803: Kiyeon An, 차민규 (CHA Minkyu) AppleGraphicsControl Available for: macOS Catalina 10.15 Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization. CVE-2019-8716: Zhiyi Zhang of Codesafe Team of Legendsec at Qi'anxin Group, Zhuo Liang of Qihoo 360 Vulcan Team Associated Domains Available for: macOS Catalina 10.15 Impact: Improper URL processing may lead to data exfiltration Description: An issue existed in the parsing of URLs. CVE-2019-8788: Juha Lindstedt of Pakastin, Mirko Tanania, Rauli Rikama of Zero Keyboard Ltd Audio Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: Processing a maliciously crafted audio file may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved state management. CVE-2019-8706: Yu Zhou of Ant-financial Light-Year Security Lab Audio Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8785: Ian Beer of Google Project Zero CVE-2019-8797: 08Tc3wBB working with SSD Secure Disclosure Books Available for: macOS Catalina 10.15 Impact: Parsing a maliciously crafted iBooks file may lead to disclosure of user information Description: A validation issue existed in the handling of symlinks. CVE-2019-8789: Gertjan Franken of imec-DistriNet, KU Leuven Contacts Available for: macOS Catalina 10.15 Impact: Processing a maliciously contact may lead to UI spoofing Description: An inconsistent user interface issue was addressed with improved state management. CVE-2017-7152: Oliver Paukstadt of Thinking Objects GmbH (to.com) CUPS Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: An attacker in a privileged network position may be able to leak sensitive user information Description: An input validation issue was addressed with improved input validation. CVE-2019-8736: Pawel Gocyla of ING Tech Poland (ingtechpoland.com) CUPS Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: Processing a maliciously crafted string may lead to heap corruption Description: A memory consumption issue was addressed with improved memory handling. CVE-2019-8767: Stephen Zeisberg CUPS Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: An attacker in a privileged position may be able to perform a denial of service attack Description: A denial of service issue was addressed with improved validation. CVE-2019-8737: Pawel Gocyla of ING Tech Poland (ingtechpoland.com) File Quarantine Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: A malicious application may be able to elevate privileges Description: This issue was addressed by removing the vulnerable code. CVE-2019-8509: CodeColorist of Ant-Financial LightYear Labs File System Events Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8798: ABC Research s.r.o. working with Trend Micro's Zero Day Initiative Graphics Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: Processing a malicious shader may result in unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues were addressed with improved input validation. CVE-2018-12152: Piotr Bania of Cisco Talos CVE-2018-12153: Piotr Bania of Cisco Talos CVE-2018-12154: Piotr Bania of Cisco Talos Graphics Driver Available for: macOS Catalina 10.15 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8784: Vasiliy Vasilyev and Ilya Finogeev of Webinar, LLC Intel Graphics Driver Available for: macOS Catalina 10.15 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8807: Yu Wang of Didi Research America IOGraphics Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2019-8759: another of 360 Nirvan Team iTunes Available for: macOS Catalina 10.15 Impact: Running the iTunes installer in an untrusted directory may result in arbitrary code execution Description: A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. CVE-2019-8801: Hou JingYi (@hjy79425575) of Qihoo 360 CERT Kernel Available for: macOS Catalina 10.15 Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization. CVE-2019-8794: 08Tc3wBB working with SSD Secure Disclosure Kernel Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6, macOS Catalina 10.15 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8786: an anonymous researcher Kernel Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: A malicious application may be able to determine kernel memory layout Description: A memory corruption issue existed in the handling of IPv6 packets. CVE-2019-8744: Zhuo Liang of Qihoo 360 Vulcan Team libxml2 Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: Multiple issues in libxml2 Description: Multiple memory corruption issues were addressed with improved input validation. CVE-2019-8749: found by OSS-Fuzz CVE-2019-8756: found by OSS-Fuzz libxslt Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: Multiple issues in libxslt Description: Multiple memory corruption issues were addressed with improved input validation. CVE-2019-8750: found by OSS-Fuzz manpages Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15 Impact: A malicious application may be able to gain root privileges Description: A validation issue was addressed with improved logic. CVE-2019-8802: Csaba Fitzl (@theevilbit) PluginKit Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: A local user may be able to check for the existence of arbitrary files Description: A logic issue was addressed with improved restrictions. CVE-2019-8708: an anonymous researcher PluginKit Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8805: Scott Knight (@sdotknight) of VMware Carbon Black TAU UIFoundation Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.6 Impact: Parsing a maliciously crafted text file may lead to disclosure of user information Description: This issue was addressed with improved checks. CVE-2019-8761: Renee Trisberg of SpectX Additional recognition CFNetwork We would like to acknowledge Lily Chen of Google for their assistance. Kernel We would like to acknowledge Brandon Azad of Google Project Zero and Jann Horn of Google Project Zero for their assistance. libresolv We would like to acknowledge enh at Google for their assistance. Postfix We would like to acknowledge Chris Barker of Puppet for their assistance. Profiles We would like to acknowledge Csaba Fitzl (@theevilbit) for their assistance. python We would like to acknowledge an anonymous researcher for their assistance. VPN We would like to acknowledge Royce Gawron of Second Son Consulting, Inc. for their assistance. Installation note: macOS Catalina 10.15.1, Security Update 2019-001 Mojave, Security Update 2019-006 High Sierra may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQJdBAEBCABHFiEEM5FaaFRjww9EJgvRBz4uGe3y0M0FAl24p5UpHHByb2R1Y3Qt c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQBz4uGe3y0M3T5w/+ MA0oNNn6fPlkGiHHzMisKLkseGIltXgSc1v01C32qZpWoCmIzxXoDN1DZ0UC1nkh fAzFMvj25wEj14L7ZXOOqaLFgf+e3ZGzius71wru92h1oaYMkspO1A0I6jPOXUU0 EtZfy6RECv7Ees4Zvj5EWXO0Xqpk2fVyEN4f/sGLtlHRkv1Do9ge6pX3JyXynF+f M0jSntJYBFMuzIX2LZFdbTgtcNhsVMhUlztz3SKbA+JF6IxertPSp9mOxaEtGnYj LgvSy9EVn98XBRt7rS8zrXCBi1OrTV21RE2HY+Twv+8lSSMRsjo6+KW7sPYd3KDy esY0zfIkZ1VSSw/sb0kBalkl/rjLeBkSsBlLiA9uWEvkH9uDNVuo4WzDIN6a89hs Zb2Aj4VjlLlKRKXRmLmpq7TkUQTVxWNMUdHttHUa/k0ODWviH/CbCKhrv0GKB9+X EOXG65J+qCzq07MPgQG/JWCFbpVVOqQyXOuKCwrDl1LIb15WMxy8vFApEcJAsrvB Z9if9NDnJxTWo9gQUcrZHrFm/humsTc+YSPSDovfIEYwbx99LkOWdnK5kiTqodxW SMQyXhAWeZqL8zzxkFjXnodsnmVXvldFVMHjqPdXuXnn6ythU4UPedklPC50bH9G Ofniqz3XXmySfVDFNFyfODEsvnoTxmGiUyJzAxAM+JM= =fvfR -----END PGP SIGNATURE----- . CVE-2019-8750: found by OSS-Fuzz VoiceOver Available for: Apple Watch Series 1 and later Impact: A person with physical access to an iOS device may be able to access contacts from the lock screen Description: The issue was addressed by restricting options offered on a locked device. Alternatively, on your watch, select "My Watch > General > About". CVE-2019-8786: an anonymous researcher Screen Time Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch 7th generation Impact: A local user may be able to record the screen without a visible screen recording indicator Description: A consistency issue existed in deciding when to show the screen recording indicator. CVE-2019-8793: Ryan Jenkins of Lake Forrest Prep School Setup Assistant Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch 7th generation Impact: An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup Description: An inconsistency in Wi-Fi network configuration settings was addressed. CVE-2019-8782: Cheolung Lee of LINE+ Security Team CVE-2019-8783: Cheolung Lee of LINE+ Graylab Security Team CVE-2019-8808: found by OSS-Fuzz CVE-2019-8811: Soyeon Park of SSLab at Georgia Tech CVE-2019-8812: an anonymous researcher CVE-2019-8814: Cheolung Lee of LINE+ Security Team CVE-2019-8816: Soyeon Park of SSLab at Georgia Tech CVE-2019-8819: Cheolung Lee of LINE+ Security Team CVE-2019-8820: Samuel Groß of Google Project Zero CVE-2019-8821: Sergei Glazunov of Google Project Zero CVE-2019-8822: Sergei Glazunov of Google Project Zero CVE-2019-8823: Sergei Glazunov of Google Project Zero WebKit Process Model Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch 7th generation Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling. Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "iOS 13.2 and iPadOS 13.2"

Trust: 2.7

sources: NVD: CVE-2019-8798 // JVNDB: JVNDB-2019-011304 // ZDI: ZDI-19-1009 // VULHUB: VHN-160233 // PACKETSTORM: 155067 // PACKETSTORM: 155065 // PACKETSTORM: 155069 // PACKETSTORM: 155058

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:ltversion:13.2

Trust: 1.0

vendor:applemodel:tvosscope:ltversion:13.2

Trust: 1.0

vendor:applemodel:ipadosscope:ltversion:13.2

Trust: 1.0

vendor:applemodel:mac os xscope:ltversion:10.15.1

Trust: 1.0

vendor:applemodel:watchosscope:ltversion:6.1

Trust: 1.0

vendor:applemodel:icloudscope:ltversion:for windows 11.0 earlier

Trust: 0.8

vendor:applemodel:icloudscope:ltversion:for windows 7.15 earlier

Trust: 0.8

vendor:applemodel:iosscope:ltversion:13.2 earlier

Trust: 0.8

vendor:applemodel:ipadosscope:ltversion:13.2 earlier

Trust: 0.8

vendor:applemodel:itunesscope:ltversion:12.10.2 for windows earlier

Trust: 0.8

vendor:applemodel:macos catalinascope:ltversion:10.15.1 earlier

Trust: 0.8

vendor:applemodel:macos high sierrascope:eqversion:10.13.6 (security update 2019-006 not applied )

Trust: 0.8

vendor:applemodel:macos mojavescope:eqversion:10.14.6 (security update 2019-001 not applied )

Trust: 0.8

vendor:applemodel:safariscope:ltversion:13.0.3 earlier

Trust: 0.8

vendor:applemodel:tvosscope:ltversion:13.2 earlier

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:6.1 earlier

Trust: 0.8

vendor:applemodel:xcodescope:ltversion:11.2 earlier

Trust: 0.8

vendor:applemodel:macosscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-19-1009 // JVNDB: JVNDB-2019-011304 // NVD: CVE-2019-8798

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-8798
value: MEDIUM

Trust: 1.0

ZDI: CVE-2019-8798
value: MEDIUM

Trust: 0.7

CNNVD: CNNVD-201910-1772
value: MEDIUM

Trust: 0.6

VULHUB: VHN-160233
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-8798
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-160233
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-8798
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

ZDI: CVE-2019-8798
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.0
impactScore: 4.0
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-19-1009 // VULHUB: VHN-160233 // CNNVD: CNNVD-201910-1772 // NVD: CVE-2019-8798

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

problemtype:CWE-119

Trust: 0.1

sources: VULHUB: VHN-160233 // NVD: CVE-2019-8798

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201910-1772

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201910-1772

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-011304

PATCH

title:About the security content of macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006url:https://support.apple.com/en-us/HT210722

Trust: 1.5

title:About the security content of iCloud for Windows 11.0url:https://support.apple.com/en-us/HT210727

Trust: 0.8

title:About the security content of iCloud for Windows 7.15url:https://support.apple.com/en-us/HT210728

Trust: 0.8

title:About the security content of iOS 13.2 and iPadOS 13.2url:https://support.apple.com/en-us/HT210721

Trust: 0.8

title:About the security content of Xcode 11.2url:https://support.apple.com/en-us/HT210729

Trust: 0.8

title:About the security content of tvOS 13.2url:https://support.apple.com/en-us/HT210723

Trust: 0.8

title:About the security content of watchOS 6.1url:https://support.apple.com/en-us/HT210724

Trust: 0.8

title:About the security content of Safari 13.0.3url:https://support.apple.com/en-us/HT210725

Trust: 0.8

title:About the security content of iTunes 12.10.2 for Windowsurl:https://support.apple.com/en-us/HT210726

Trust: 0.8

title:Mac に搭載されている macOS を調べるurl:https://support.apple.com/ja-jp/HT201260

Trust: 0.8

title:Multiple Apple product File System Events Fixes for component security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=105726

Trust: 0.6

sources: ZDI: ZDI-19-1009 // JVNDB: JVNDB-2019-011304 // CNNVD: CNNVD-201910-1772

EXTERNAL IDS

db:NVDid:CVE-2019-8798

Trust: 3.6

db:ZDIid:ZDI-19-1009

Trust: 1.3

db:JVNid:JVNVU96749516

Trust: 0.8

db:JVNDBid:JVNDB-2019-011304

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-8613

Trust: 0.7

db:CNNVDid:CNNVD-201910-1772

Trust: 0.7

db:PACKETSTORMid:155069

Trust: 0.7

db:AUSCERTid:ESB-2019.4013

Trust: 0.6

db:VULHUBid:VHN-160233

Trust: 0.1

db:PACKETSTORMid:155067

Trust: 0.1

db:PACKETSTORMid:155065

Trust: 0.1

db:PACKETSTORMid:155058

Trust: 0.1

sources: ZDI: ZDI-19-1009 // VULHUB: VHN-160233 // JVNDB: JVNDB-2019-011304 // PACKETSTORM: 155067 // PACKETSTORM: 155065 // PACKETSTORM: 155069 // PACKETSTORM: 155058 // CNNVD: CNNVD-201910-1772 // NVD: CVE-2019-8798

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-8798

Trust: 1.8

url:https://support.apple.com/ht210721

Trust: 1.7

url:https://support.apple.com/ht210722

Trust: 1.7

url:https://support.apple.com/ht210723

Trust: 1.7

url:https://support.apple.com/ht210724

Trust: 1.7

url:https://support.apple.com/en-us/ht210722

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8785

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8797

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8786

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8787

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8794

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8812

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8803

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8816

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8820

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8811

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8750

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8822

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8813

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8823

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8814

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8815

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8788

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8789

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8819

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8782

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8783

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8821

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8784

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8795

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8764

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8765

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8766

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8804

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8775

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8793

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8743

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8747

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8788

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8803

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8815

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8766

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8735

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8789

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8804

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8816

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8775

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8793

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8805

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8710

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8819

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8782

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8794

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8807

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8743

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8820

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8783

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8795

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8811

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8747

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8821

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8784

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8797

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8812

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8750

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8822

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8785

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8798

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8813

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8764

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8823

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8786

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8802

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8814

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8765

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8787

Trust: 0.8

url:https://jvn.jp/vu/jvnvu96749516/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-8802

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-8805

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-8710

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-8807

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-8735

Trust: 0.8

url:https://support.apple.com/en-au/ht201222

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.4013/

Trust: 0.6

url:https://vigilance.fr/vulnerability/apple-macos-multiple-vulnerabilities-30747

Trust: 0.6

url:https://packetstormsecurity.com/files/155069/apple-security-advisory-2019-10-29-3.html

Trust: 0.6

url:https://www.zerodayinitiative.com/advisories/zdi-19-1009/

Trust: 0.6

url:https://support.apple.com/en-us/ht210723

Trust: 0.6

url:https://support.apple.com/kb/ht201222

Trust: 0.4

url:https://www.apple.com/support/security/pgp/

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2017-7152

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8808

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8706

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8767

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8744

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8716

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8736

Trust: 0.1

url:https://support.apple.com/downloads/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8708

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8509

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8756

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8801

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12153

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8737

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8749

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12154

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8759

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8715

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12152

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8761

Trust: 0.1

url:https://support.apple.com/kb/ht204641

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

sources: ZDI: ZDI-19-1009 // VULHUB: VHN-160233 // JVNDB: JVNDB-2019-011304 // PACKETSTORM: 155067 // PACKETSTORM: 155065 // PACKETSTORM: 155069 // PACKETSTORM: 155058 // CNNVD: CNNVD-201910-1772 // NVD: CVE-2019-8798

CREDITS

ABC Research s.r.o.

Trust: 0.7

sources: ZDI: ZDI-19-1009

SOURCES

db:ZDIid:ZDI-19-1009
db:VULHUBid:VHN-160233
db:JVNDBid:JVNDB-2019-011304
db:PACKETSTORMid:155067
db:PACKETSTORMid:155065
db:PACKETSTORMid:155069
db:PACKETSTORMid:155058
db:CNNVDid:CNNVD-201910-1772
db:NVDid:CVE-2019-8798

LAST UPDATE DATE

2024-08-14T12:59:06.621000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-19-1009date:2019-12-11T00:00:00
db:VULHUBid:VHN-160233date:2019-12-23T00:00:00
db:JVNDBid:JVNDB-2019-011304date:2020-01-07T00:00:00
db:CNNVDid:CNNVD-201910-1772date:2021-11-03T00:00:00
db:NVDid:CVE-2019-8798date:2021-07-21T11:39:23.747

SOURCES RELEASE DATE

db:ZDIid:ZDI-19-1009date:2019-12-11T00:00:00
db:VULHUBid:VHN-160233date:2019-12-18T00:00:00
db:JVNDBid:JVNDB-2019-011304date:2019-11-01T00:00:00
db:PACKETSTORMid:155067date:2019-11-01T17:11:03
db:PACKETSTORMid:155065date:2019-11-01T17:10:20
db:PACKETSTORMid:155069date:2019-11-01T17:11:43
db:PACKETSTORMid:155058date:2019-11-01T17:05:53
db:CNNVDid:CNNVD-201910-1772date:2019-10-30T00:00:00
db:NVDid:CVE-2019-8798date:2019-12-18T18:15:42.413