ID

VAR-201912-0562


CVE

CVE-2019-8745


TITLE

plural Apple Updates to product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2019-012754

DESCRIPTION

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing a maliciously crafted text file may lead to arbitrary code execution. Apple Has released an update for each product.The expected impact depends on each vulnerability, but can be affected as follows: * information leak * Falsification of information * Arbitrary code execution * Service operation interruption (DoS) * Privilege escalation * Authentication bypass. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the CFFromShiftJISLen function. Crafted data in a DOC file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. are all products of Apple (Apple). The product supports storage of music, photos, App and contacts, etc. Apple macOS Catalina is a dedicated operating system developed for Mac computers. UIFoundation is one of the UI framework components. CVE-2019-8748: Lilang Wu and Moony Li of TrendMicro Mobile Security Research Team apache_mod_php Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: Multiple issues in PHP Description: Multiple issues were addressed by updating to PHP version 7.3.8. CVE-2019-8706: Yu Zhou of Ant-financial Light-Year Security Lab Entry added October 29, 2019 Books Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: Parsing a maliciously crafted iBooks file may lead to a persistent denial-of-service Description: A resource exhaustion issue was addressed with improved input validation. CVE-2019-8825: Found by GWP-ASan in Google Chrome Entry added October 29, 2019 Crash Reporter Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: The "Share Mac Analytics" setting may not be disabled when a user deselects the switch to share analytics Description: A race condition existed when reading and writing user preferences. CVE-2019-8757: William Cerniuk of Core Development, LLC CUPS Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: An attacker in a privileged network position may be able to leak sensitive user information Description: An input validation issue was addressed with improved input validation. CVE-2019-8767: Stephen Zeisberg Entry added October 29, 2019 CUPS Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: An attacker in a privileged position may be able to perform a denial of service attack Description: A denial of service issue was addressed with improved validation. CVE-2019-8758: Lilang Wu and Moony Li of Trend Micro IOGraphics Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: A malicious application may be able to determine kernel memory layout Description: A logic issue was addressed with improved restrictions. CVE-2019-8750: found by OSS-Fuzz Entry added October 29, 2019 mDNSResponder Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: An attacker in physical proximity may be able to passively observe device names in AWDL communications Description: This issue was resolved by replacing device names with a random identifier. CVE-2019-8730: Jamie Blumberg (@jamie_blumberg) of Virginia Polytechnic Institute and State University PDFKit Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: An attacker may be able to exfiltrate the contents of an encrypted PDF Description: An issue existed in the handling of links in encrypted PDFs. CVE-2019-8701: Simon Huang(@HuangShaomang), Rong Fan(@fanrong1992) and pjf of IceSword Lab of Qihoo 360 UIFoundation Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: Parsing a maliciously crafted text file may lead to disclosure of user information Description: This issue was addressed with improved checks. Diaz (coldpointblue) WebKit Available for: MacBook (Early 2015 and later), MacBook Air (Mid 2012 and later), MacBook Pro (Mid 2012 and later), Mac mini (Late 2012 and later), iMac (Late 2012 and later), iMac Pro (all models), Mac Pro (Late 2013 and later) Impact: Visiting a maliciously crafted website may reveal browsing history Description: An issue existed in the drawing of web page elements. boringssl We would like to acknowledge Nimrod Aviram of Tel Aviv University, Robert Merget of Ruhr University Bochum, Juraj Somorovsky of Ruhr University Bochum and Thijs Alkemade (@xnyhps) of Computest for their assistance. Alternatively, on your watch, select "My Watch > General > About". -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-10-29-6 Additional information for APPLE-SA-2019-9-26-3 iOS 13 iOS 13 addresses the following: Bluetooth Available for: iPhone 6s and later Impact: Notification previews may show on Bluetooth accessories even when previews are disabled Description: A logic issue existed with the display of notification previews. CVE-2019-8711: Arjang of MARK ANTHONY GROUP INC., Cemil Ozkebapci (@cemilozkebapci) of Garanti BBVA, Oguzhan Meral of Deloitte Consulting, Ömer Bozdoğan-Ramazan Atıl Anadolu Lisesi Adana/TÜRKİYE CFNetwork Available for: iPhone 6s and later Impact: Processing maliciously crafted web content may lead to a cross site scripting attack Description: This issue was addressed with improved checks. CVE-2019-8753: Łukasz Pilorz of Standard Chartered GBS Poland Entry added October 29, 2019 CoreAudio Available for: iPhone 6s and later Impact: Processing a maliciously crafted movie may result in the disclosure of process memory Description: A memory corruption issue was addressed with improved validation. CVE-2019-8705: riusksk of VulWar Corp working with Trend Micro's Zero Day Initiative CoreCrypto Available for: iPhone 6s and later Impact: Processing a large input may lead to a denial of service Description: A denial of service issue was addressed with improved input validation. CVE-2019-8741: Nicky Mouha of NIST Entry added October 29, 2019 CoreMedia Available for: iPhone 6s and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved state management. CVE-2019-8825: Found by GWP-ASan in Google Chrome Entry added October 29, 2019 Face ID Available for: iPhone 6s and later Impact: A 3D model constructed to look like the enrolled user may authenticate via Face ID Description: This issue was addressed by improving Face ID machine learning models. CVE-2019-8760: Wish Wu (吴潍浠 @wish_wu) of Ant-financial Light-Year Security Lab Foundation Available for: iPhone 6s and later Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution Description: An out-of-bounds read was addressed with improved input validation. CVE-2019-8641: Samuel Groß and Natalie Silvanovich of Google Project Zero CVE-2019-8746: Natalie Silvanovich and Samuel Groß of Google Project Zero Entry added October 29, 2019 IOUSBDeviceFamily Available for: iPhone 6s and later Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8718: Joshua Hill and Sem Voigtländer Entry added October 29, 2019 Kernel Available for: iPhone 6s and later Impact: A local app may be able to read a persistent account identifier Description: A validation issue was addressed with improved logic. CVE-2019-8809: Apple Entry added October 29, 2019 Kernel Available for: iPhone 6s and later Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved state management. CVE-2019-8709: derrek (@derrekr6) [confirmed]derrek (@derrekr6) Entry added October 29, 2019 Kernel Available for: iPhone 6s and later Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8717: Jann Horn of Google Project Zero Entry added October 29, 2019 Kernel Available for: iPhone 6s and later Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8712: Mohamed Ghannam (@_simo36) Entry added October 29, 2019 Kernel Available for: iPhone 6s and later Impact: A malicious application may be able to determine kernel memory layout Description: A memory corruption issue existed in the handling of IPv6 packets. CVE-2019-8744: Zhuo Liang of Qihoo 360 Vulcan Team Entry added October 29, 2019 Keyboards Available for: iPhone 6s and later Impact: A local user may be able to leak sensitive user information Description: An authentication issue was addressed with improved state management. CVE-2019-8704: 王 邦 宇 (wAnyBug.Com) of SAINTSEC libxml2 Available for: iPhone 6s and later Impact: Multiple issues in libxml2 Description: Multiple memory corruption issues were addressed with improved input validation. CVE-2019-8749: found by OSS-Fuzz CVE-2019-8756: found by OSS-Fuzz Entry added October 29, 2019 Messages Available for: iPhone 6s and later Impact: A person with physical access to an iOS device may be able to access contacts from the lock screen Description: The issue was addressed by restricting options offered on a locked device. CVE-2019-8742: videosdebarraquito Notes Available for: iPhone 6s and later Impact: A local user may be able to view a user's locked notes Description: The contents of locked notes sometimes appeared in search results. CVE-2019-8730: Jamie Blumberg (@jamie_blumberg) of Virginia Polytechnic Institute and State University Entry added October 29, 2019 PluginKit Available for: iPhone 6s and later Impact: A local user may be able to check for the existence of arbitrary files Description: A logic issue was addressed with improved restrictions. CVE-2019-8708: an anonymous researcher Entry added October 29, 2019 PluginKit Available for: iPhone 6s and later Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2019-8715: an anonymous researcher Entry added October 29, 2019 Quick Look Available for: iPhone 6s and later Impact: Processing a maliciously crafted file may disclose user information Description: A permissions issue existed in which execute permission was incorrectly granted. CVE-2019-8731: Saif Hamed Hamdan Al Hinai of Oman National CERT, Yiğit Can YILMAZ (@yilmazcanyigit) Safari Available for: iPhone 6s and later Impact: Visiting a malicious website may lead to address bar spoofing Description: A logic issue was addressed with improved state management. CVE-2019-8745: riusksk of VulWar Corp working with Trend Micro's Zero Day Initiative Entry added October 29, 2019 WebKit Available for: iPhone 6s and later Impact: Maliciously crafted web content may violate iframe sandboxing policy Description: This issue was addressed with improved iframe sandbox enforcement. CVE-2019-8771: Eliya Stein of Confiant Entry added October 29, 2019 WebKit Available for: iPhone 6s and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2019-8707: an anonymous researcher working with Trend Micro's Zero Day Initiative, cc working with Trend Micro Zero Day Initiative CVE-2019-8726: Jihui Lu of Tencent KeenLab CVE-2019-8728: Junho Jang of LINE Security Team and Hanul Choi of ABLY Corporation CVE-2019-8733: Sergei Glazunov of Google Project Zero CVE-2019-8734: found by OSS-Fuzz CVE-2019-8735: G. Geshev working with Trend Micro Zero Day Initiative Entry added October 29, 2019 WebKit Available for: iPhone 6s and later Impact: A user may be unable to delete browsing history items Description: "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. CVE-2019-8768: Hugo S. Diaz (coldpointblue) Entry added October 29, 2019 WebKit Available for: iPhone 6s and later Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management. CVE-2019-8625: Sergei Glazunov of Google Project Zero CVE-2019-8719: Sergei Glazunov of Google Project Zero CVE-2019-8764: Sergei Glazunov of Google Project Zero Entry added October 29, 2019 WebKit Page Loading Available for: iPhone 6s and later Impact: Processing maliciously crafted web content may lead to universal cross site scripting Description: A logic issue was addressed with improved state management. CVE-2019-8674: Sergei Glazunov of Google Project Zero Additional recognition AppleRTC We would like to acknowledge Vitaly Cheptsov for their assistance. Audio We would like to acknowledge riusksk of VulWar Corp working with Trend Micro's Zero Day Initiative for their assistance. Bluetooth We would like to acknowledge Jan Ruge of TU Darmstadt, Secure Mobile Networking Lab, Jiska Classen of TU Darmstadt, Secure Mobile Networking Lab, Francesco Gringoli of University of Brescia, Dennis Heinze of TU Darmstadt, Secure Mobile Networking Lab for their assistance. boringssl We would like to acknowledge Thijs Alkemade (@xnyhps) of Computest for their assistance. Control Center We would like to acknowledge Brandon Sellers for their assistance. HomeKit We would like to acknowledge Tian Zhang for their assistance. Kernel We would like to acknowledge Brandon Azad of Google Project Zero for their assistance. Keyboard We would like to acknowledge an anonymous researcher for their assistance. Mail We would like to acknowledge Kenneth Hyndycz for their assistance. mDNSResponder We would like to acknowledge Gregor Lang of e.solutions GmbH for their assistance. Profiles We would like to acknowledge Erik Johnson of Vernon Hills High School and James Seeley (@Code4iOS) of Shriver Job Corps for their assistance. SafariViewController We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for their assistance. VPN We would like to acknowledge Royce Gawron of Second Son Consulting, Inc. for their assistance. WebKit We would like to acknowledge MinJeong Kim of Information Security Lab, Chungnam National University, JaeCheol Ryou of the Information Security Lab, Chungnam National University in South Korea, Yiğit Can YILMAZ (@yilmazcanyigit), Zhihua Yao of DBAPPSecurity Zion Lab, an anonymous researcher, and cc working with Trend Micro's Zero Day Initiative for their assistance. Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "iOS 13". Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEM5FaaFRjww9EJgvRBz4uGe3y0M0FAl24s3oACgkQBz4uGe3y 0M1GMxAAnwBO9htU2i7+SHsXiEt2xJbjilLMM9V5LObjUWqaHXOxdQuYiPxFy9lR neTOHwR2z1f3L3UPkGut28i24w7fwHVBdFh7w5p5RXlBf7tcRmFhKBUkYIhQ90Qj jO6DXiCL9InCBVs2nW9Fr4yYV13kdoES6MfguyldGVpQMkyUcZ3F2XK0RCHNqEgz h+1dR/uws3Ce+HNbb7wnqe4UzAI5DJUR/vH98+fWTl5P6CCaoZrv53vaxErLRBXi gn/4rtzw+wDlThlrpkE5MwxmvLMF2ZqjUhOSVzKb3qXK+RFgE9FH8SKEBKkCxAa+ 8/vZu+zdbN6KCzO608TXH9rNO2LbtQqTlO/jHGTJ30UEaKo9PyFozGkCE6XkWmFU xtayVkSL08drJEgm+CB80g//hr2CESF0fMHFe8yQYeN2uL5yQxoavyub8E/nPKn1 v32Z6Z2fpGzP3eCLYbV93cBcdJaeXTdib47vvodyYFfFEja7xrv0AvPAbSSm98DK VtFw3eNAKRbmIEAeY4b1uhdB+qUiqMEWqh0sd97+chY2Do90/4IG/3caLc0pTpDt huDUQs/IbSujrdjCWSfz35qU4u9sxPpM8wQR2M7mdfY9qGp+Xgfh/MprSZ4wOuS3 PAAs5Pdr9GfymsB+CDpMEr+DiTOza6SUjIadZ+j2FWaklzg7h1A= =NYIZ -----END PGP SIGNATURE-----

Trust: 3.06

sources: NVD: CVE-2019-8745 // JVNDB: JVNDB-2019-012754 // ZDI: ZDI-19-863 // VULHUB: VHN-160180 // PACKETSTORM: 155061 // PACKETSTORM: 155066 // PACKETSTORM: 154771 // PACKETSTORM: 154769 // PACKETSTORM: 154780 // PACKETSTORM: 155064 // PACKETSTORM: 155062 // PACKETSTORM: 154768

AFFECTED PRODUCTS

vendor:applemodel:itunesscope:ltversion:12.10.1

Trust: 1.0

vendor:applemodel:icloudscope:ltversion:7.14

Trust: 1.0

vendor:applemodel:tvosscope:ltversion:13

Trust: 1.0

vendor:applemodel:icloudscope:ltversion:10.7

Trust: 1.0

vendor:applemodel:icloudscope:gteversion:10.0

Trust: 1.0

vendor:applemodel:mac os xscope:ltversion:10.15

Trust: 1.0

vendor:applemodel:icloudscope:ltversion:for windows 10.9 earlier

Trust: 0.8

vendor:applemodel:icloudscope:ltversion:for windows 7.16 (includes aas 8.2) earlier

Trust: 0.8

vendor:applemodel:iosscope:ltversion:12.4.4 earlier

Trust: 0.8

vendor:applemodel:iosscope:ltversion:13.3 earlier

Trust: 0.8

vendor:applemodel:ipadosscope:ltversion:13.3 earlier

Trust: 0.8

vendor:applemodel:itunesscope:ltversion:12.10.3 for windows earlier

Trust: 0.8

vendor:applemodel:macos catalinascope:ltversion:10.15.2 earlier

Trust: 0.8

vendor:applemodel:macos high sierrascope:eqversion:10.13.6 (security update 2019-007 not applied )

Trust: 0.8

vendor:applemodel:macos mojavescope:eqversion:10.14.6 (security update 2019-002 not applied )

Trust: 0.8

vendor:applemodel:safariscope:ltversion:13.0.4 earlier

Trust: 0.8

vendor:applemodel:tvosscope:ltversion:13.3 earlier

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:5.3.4 earlier

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:6.1.1 earlier

Trust: 0.8

vendor:applemodel:xcodescope:ltversion:11.3 earlier

Trust: 0.8

vendor:applemodel:macosscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-19-863 // JVNDB: JVNDB-2019-012754 // NVD: CVE-2019-8745

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-8745
value: HIGH

Trust: 1.0

ZDI: CVE-2019-8745
value: HIGH

Trust: 0.7

CNNVD: CNNVD-201910-392
value: HIGH

Trust: 0.6

VULHUB: VHN-160180
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-8745
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-160180
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-8745
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

ZDI: CVE-2019-8745
baseSeverity: HIGH
baseScore: 7.8
vectorString: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-19-863 // VULHUB: VHN-160180 // CNNVD: CNNVD-201910-392 // NVD: CVE-2019-8745

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.1

sources: VULHUB: VHN-160180 // NVD: CVE-2019-8745

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201910-392

TYPE

overflow, code execution, xss

Trust: 0.7

sources: PACKETSTORM: 155061 // PACKETSTORM: 155066 // PACKETSTORM: 154771 // PACKETSTORM: 154769 // PACKETSTORM: 154780 // PACKETSTORM: 155064 // PACKETSTORM: 155062

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-012754

PATCH

title:About the security content of Safari 13.0.4url:https://support.apple.com/en-us/HT210792

Trust: 0.8

title:About the security content of Xcode 11.3url:https://support.apple.com/en-us/HT210796

Trust: 0.8

title:Mac に搭載されている macOS を調べるurl:https://support.apple.com/ja-jp/HT201260

Trust: 0.8

title:About the security content of iOS 13.3 and iPadOS 13.3url:https://support.apple.com/en-us/HT210785

Trust: 0.8

title:About the security content of iCloud for Windows 10.9url:https://support.apple.com/en-us/HT210794

Trust: 0.8

title:About the security content of iOS 12.4.4url:https://support.apple.com/en-us/HT210787

Trust: 0.8

title:About the security content of iCloud for Windows 7.16 (includes AAS 8.2)url:https://support.apple.com/en-us/HT210795

Trust: 0.8

title:About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierraurl:https://support.apple.com/en-us/HT210788

Trust: 0.8

title:About the security content of iTunes 12.10.3 for Windowsurl:https://support.apple.com/en-us/HT210793

Trust: 0.8

title:About the security content of watchOS 6.1.1url:https://support.apple.com/en-us/HT210789

Trust: 0.8

title:About the security content of tvOS 13.3url:https://support.apple.com/en-us/HT210790

Trust: 0.8

title:About the security content of watchOS 5.3.4url:https://support.apple.com/en-us/HT210791

Trust: 0.8

title:Apple has issued an update to correct this vulnerability.url:https://support.apple.com/en-us/HT210634

Trust: 0.7

title:Apple macOS , iCloud and iTunes Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=99070

Trust: 0.6

sources: ZDI: ZDI-19-863 // JVNDB: JVNDB-2019-012754 // CNNVD: CNNVD-201910-392

EXTERNAL IDS

db:NVDid:CVE-2019-8745

Trust: 4.0

db:ZDIid:ZDI-19-863

Trust: 1.3

db:JVNid:JVNVU99404393

Trust: 0.8

db:JVNDBid:JVNDB-2019-012754

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-8588

Trust: 0.7

db:CNNVDid:CNNVD-201910-392

Trust: 0.7

db:PACKETSTORMid:155066

Trust: 0.7

db:PACKETSTORMid:154780

Trust: 0.7

db:AUSCERTid:ESB-2019.3760

Trust: 0.6

db:VULHUBid:VHN-160180

Trust: 0.1

db:PACKETSTORMid:155061

Trust: 0.1

db:PACKETSTORMid:154771

Trust: 0.1

db:PACKETSTORMid:154769

Trust: 0.1

db:PACKETSTORMid:155064

Trust: 0.1

db:PACKETSTORMid:155062

Trust: 0.1

db:PACKETSTORMid:154768

Trust: 0.1

sources: ZDI: ZDI-19-863 // VULHUB: VHN-160180 // JVNDB: JVNDB-2019-012754 // PACKETSTORM: 155061 // PACKETSTORM: 155066 // PACKETSTORM: 154771 // PACKETSTORM: 154769 // PACKETSTORM: 154780 // PACKETSTORM: 155064 // PACKETSTORM: 155062 // PACKETSTORM: 154768 // CNNVD: CNNVD-201910-392 // NVD: CVE-2019-8745

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-8745

Trust: 2.2

url:https://support.apple.com/kb/ht210722

Trust: 1.7

url:https://support.apple.com/ht210634

Trust: 1.7

url:https://support.apple.com/ht210635

Trust: 1.7

url:https://support.apple.com/ht210636

Trust: 1.7

url:https://support.apple.com/ht210637

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-8719

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8726

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8733

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8625

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8705

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8707

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8717

Trust: 1.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8763

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8730

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8758

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8701

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8748

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8755

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8757

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-8768

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8769

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8770

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8772

Trust: 0.9

url:https://nvd.nist.gov/vuln/detail/cve-2019-8781

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8701

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8745

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8770

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8705

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8748

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8772

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8707

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8755

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8781

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8717

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8757

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8719

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8758

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8726

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8763

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8730

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8768

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8625

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8733

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-8769

Trust: 0.8

url:https://jvn.jp/vu/jvnvu99404393/

Trust: 0.8

url:https://support.apple.com/kb/ht201222

Trust: 0.8

url:https://www.apple.com/support/security/pgp/

Trust: 0.8

url:https://support.apple.com/en-us/ht210634

Trust: 0.7

url:https://support.apple.com/en-au/ht201222

Trust: 0.6

url:https://support.apple.com/en-us/ht210637

Trust: 0.6

url:https://packetstormsecurity.com/files/155066/apple-security-advisory-2019-10-29-10.html

Trust: 0.6

url:https://support.apple.com/en-us/ht210636

Trust: 0.6

url:https://packetstormsecurity.com/files/154780/apple-security-advisory-2019-10-07-4.html

Trust: 0.6

url:https://www.zerodayinitiative.com/advisories/zdi-19-863/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3760/

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-8735

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2019-8744

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-8746

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-8749

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-8709

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-8741

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2019-8753

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8706

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8728

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8734

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8712

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8718

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-8710

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8750

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8752

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8751

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8740

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8704

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-11042

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-11041

Trust: 0.2

url:https://support.apple.com/downloads/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8708

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8756

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8715

Trust: 0.2

url:https://support.apple.com/ht204283

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8641

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2019-8747

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8743

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8736

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8509

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12153

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8737

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12154

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-12152

Trust: 0.1

url:https://www.apple.com/itunes/download/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8720

Trust: 0.1

url:https://support.apple.com/kb/ht204641

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8773

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8809

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8799

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8731

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8727

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8711

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8742

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-8674

Trust: 0.1

sources: ZDI: ZDI-19-863 // VULHUB: VHN-160180 // JVNDB: JVNDB-2019-012754 // PACKETSTORM: 155061 // PACKETSTORM: 155066 // PACKETSTORM: 154771 // PACKETSTORM: 154769 // PACKETSTORM: 154780 // PACKETSTORM: 155064 // PACKETSTORM: 155062 // PACKETSTORM: 154768 // CNNVD: CNNVD-201910-392 // NVD: CVE-2019-8745

CREDITS

Apple

Trust: 0.8

sources: PACKETSTORM: 155061 // PACKETSTORM: 155066 // PACKETSTORM: 154771 // PACKETSTORM: 154769 // PACKETSTORM: 154780 // PACKETSTORM: 155064 // PACKETSTORM: 155062 // PACKETSTORM: 154768

SOURCES

db:ZDIid:ZDI-19-863
db:VULHUBid:VHN-160180
db:JVNDBid:JVNDB-2019-012754
db:PACKETSTORMid:155061
db:PACKETSTORMid:155066
db:PACKETSTORMid:154771
db:PACKETSTORMid:154769
db:PACKETSTORMid:154780
db:PACKETSTORMid:155064
db:PACKETSTORMid:155062
db:PACKETSTORMid:154768
db:CNNVDid:CNNVD-201910-392
db:NVDid:CVE-2019-8745

LAST UPDATE DATE

2024-09-19T00:46:44.253000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-19-863date:2019-10-08T00:00:00
db:VULHUBid:VHN-160180date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-012754date:2020-01-07T00:00:00
db:CNNVDid:CNNVD-201910-392date:2021-11-03T00:00:00
db:NVDid:CVE-2019-8745date:2020-08-24T17:37:01.140

SOURCES RELEASE DATE

db:ZDIid:ZDI-19-863date:2019-10-08T00:00:00
db:VULHUBid:VHN-160180date:2019-12-18T00:00:00
db:JVNDBid:JVNDB-2019-012754date:2019-12-12T00:00:00
db:PACKETSTORMid:155061date:2019-11-01T17:08:00
db:PACKETSTORMid:155066date:2019-11-01T17:10:40
db:PACKETSTORMid:154771date:2019-10-08T20:00:56
db:PACKETSTORMid:154769date:2019-10-08T19:59:44
db:PACKETSTORMid:154780date:2019-10-08T20:44:48
db:PACKETSTORMid:155064date:2019-11-01T17:09:58
db:PACKETSTORMid:155062date:2019-11-01T17:08:23
db:PACKETSTORMid:154768date:2019-10-08T19:59:26
db:CNNVDid:CNNVD-201910-392date:2019-10-08T00:00:00
db:NVDid:CVE-2019-8745date:2019-12-18T18:15:38.443