First published: Tue Jan 22 2019(Updated: )
QuartzCore. An out-of-bounds read was addressed with improved input validation.
Credit: product-security@apple.com Yufeng Ruan Chaitin Security Research Lab product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.14.3 | |
Apple macOS Mojave | <10.14.3 | 10.14.3 |
Apple High Sierra | ||
Apple Sierra | ||
<10.14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-6220 is a vulnerability in QuartzCore in Apple macOS Mojave and earlier versions that allows an application to read restricted memory due to an out-of-bounds read vulnerability.
The severity of CVE-2019-6220 is medium, with a severity value of 5.5.
CVE-2019-6220 affects macOS Mojave versions up to but not including 10.14.3, allowing an application to read restricted memory.
To fix CVE-2019-6220 in macOS Mojave, update to version 10.14.3 or later.
You can find more information about CVE-2019-6220 in the following references: [Apple Support](https://support.apple.com/en-us/HT209446), [SecurityFocus](http://www.securityfocus.com/bid/106693), and [Apple HT209446](https://support.apple.com/HT209446).