CVE-2019-8790
published 2020-10-27CVE-2019-8790: This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.35%
26.9th percentile
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | swift | < 5.1.1 | 5.1.1 |
| apple | swift_5.1.1_for_ubuntu | — | — |
| apple | swift_for_ubuntu | >= unspecified < 5.1 | 5.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5v59-m956-6fv5: This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5
ghsa_unreviewed·2022-05-24
CVE-2019-8790 [MEDIUM] CWE-922 GHSA-5v59-m956-6fv5: This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5
This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.
Apple
CVE-2019-8790: Swift 5.1.1 for Ubuntu
vendor_apple·2019-10-11·CVSS 5.5
CVE-2019-8790 [MEDIUM] CVE-2019-8790: Swift 5.1.1 for Ubuntu
Apple Security Update: About the security content of Swift 5.1.1 for Ubuntu
Product: Swift 5.1.1 for Ubuntu
CVE: CVE-2019-8790
Component: Foundation
Impact: Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure
Description: This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-27
Published