CVE-2019-8830Out-of-bounds Read in Apple IOS AND Ipados

CWE-125Out-of-bounds Read9 documents4 sources
Severity
8.8HIGHNVD
EPSS
1.7%
top 17.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iOS 12.4.4, watchOS 5.3.4. Processing malicious video via FaceTime may lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

NVDapple/watchos6.0.06.1.1+1
NVDapple/tvos< 13.3
CVEListV5apple/macosunspecified10.15+3
NVDapple/ipados< 13.3
NVDapple/mac_os_x< 10.15.2

🔴Vulnerability Details

2
GHSA
GHSA-96wq-m98v-ph79: An out-of-bounds read was addressed with improved input validation2022-05-24
CVEList
CVE-2019-8830: An out-of-bounds read was addressed with improved input validation2020-10-27

📋Vendor Advisories

6
Apple
CVE-2019-8830: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra2019-12-10
Apple
CVE-2019-8830: watchOS 6.1.12019-12-10
Apple
CVE-2019-8830: iOS 13.3 and iPadOS 13.32019-12-10
Apple
CVE-2019-8830: tvOS 13.32019-12-10
Apple
CVE-2019-8830: iOS 12.4.42019-12-10
CVE-2019-8830 — Out-of-bounds Read in Apple | cvebase