CVE-2019-8679

low
Published 2019-11-05 ยท Modified 2019-11-05
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.5

Description

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2019-8679 NameCVE-2019-8679 DescriptionMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution. SourceCVE (at NVD; CERT, ENISA, LWN,โ€ฆ

CVE-2019-8679

NameCVE-2019-8679
DescriptionMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-4515-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
webkit2gtk (PTS)bullseye2.44.2-1~deb11u1fixed
bullseye (security)2.50.6-1~deb11u1fixed
bookworm, bookworm (security)2.50.6-1~deb12u1fixed
trixie (security), trixie2.52.3-2~deb13u1fixed
forky2.52.3-2fixed
sid2.52.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
webkit2gtksourcebuster2.24.4-1~deb10u1DSA-4515-1
webkit2gtksource(unstable)2.24.2-1

Notes

[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
[jessie] - webkit2gtk <ignored> (Not covered by security support in jessie)
https://webkitgtk.org/security/WSA-2019-0004.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)[jessie] - webkit2gtk <ignored> (Not covered by security support in jessie)https://webkitgtk.org/security/WSA-2019-0004.html

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed libpurple-devel-2.13.0-5.el8.x86_64.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.24.2-1
sid Fixed 2.24.2-1
forky Fixed 2.24.2-1
bullseye Fixed 2.24.2-1
bookworm Fixed 2.24.2-1
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.