First published: Mon May 13 2019(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. Processing a maliciously crafted movie file may lead to arbitrary code execution.
Credit: riusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <12.3 | |
Apple Mac OS X | <10.14.5 | |
Apple tvOS | <12.3 | |
Apple watchOS | <5.2.1 | |
Apple watchOS | <5.2.1 | 5.2.1 |
Apple iOS | <12.3 | 12.3 |
Apple tvOS | <12.3 | 12.3 |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2019-8585.
The severity level of CVE-2019-8585 is high.
CVE-2019-8585 is an out-of-bounds read vulnerability that is triggered when processing a maliciously crafted movie file, which may lead to arbitrary code execution.
The affected Apple products include macOS Mojave (up to version 10.14.5), iOS (up to version 12.3), tvOS (up to version 12.3), and watchOS (up to version 5.2.1).
To fix CVE-2019-8585, it is recommended to update to iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, or watchOS 5.2.1, depending on the affected product.