First published: Fri Sep 20 2019(Updated: )
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to arbitrary code execution.
Credit: product-security@apple.com Pan ZhenPeng @Peterpan0927 Qihoo 360 Nirvan TeamPan ZhenPeng @Peterpan0927 Qihoo 360 Nirvan Team
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Xcode | <11.0 | |
Apple Xcode | <11.0 | 11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8739 is a vulnerability related to otool, a memory corruption issue that allows for arbitrary code execution.
CVE-2019-8739 affects Apple Xcode versions prior to 11.0, allowing arbitrary code execution when processing a malicious file.
The severity of CVE-2019-8739 is high, with a CVSS score of 7.8.
Yes, the issue is fixed in Xcode 11.0, so updating to this version will resolve the vulnerability.
More information about CVE-2019-8739 can be found at the following references: [link1], [link2].