First published: Thu Sep 19 2019(Updated: )
libxml2. Multiple memory corruption issues were addressed with improved input validation.
Credit: found by OSS-Fuzz product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13 | 13 |
macOS Catalina | <10.15.1 | 10.15.1 |
macOS Catalina | <10.15 | 10.15 |
Apple iOS, iPadOS, and watchOS | <13 | 13 |
Apple iOS, iPadOS, and watchOS | <6 | 6 |
Apple iCloud | <7.14 | 7.14 |
Apple iCloud | <10.7 | 10.7 |
iTunes | <12.10.1 | 12.10.1 |
iCloud for Windows | <7.14 | |
iCloud for Windows | >=10.0<10.7 | |
iTunes | <12.10.1 | |
Apple iOS and macOS | <10.15 | |
tvOS | <13 | |
Apple iOS, iPadOS, and watchOS | <6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-8756 is a vulnerability in libxml2 that allows attackers to cause a denial of service or execute arbitrary code.
The severity of CVE-2019-8756 is critical with a CVSS score of 9.8.
macOS Catalina 10.15 up to 10.15.1, iOS 13, watchOS 6, iCloud for Windows 7.14 up to 10.7, tvOS 13, and iTunes 12.10.1 for Windows are affected by CVE-2019-8756.
To fix CVE-2019-8756, update to macOS Catalina 10.15.1 or later, iOS 13 or later, watchOS 6 or later, iCloud for Windows 10.7 or later, tvOS 13 or later, and iTunes 12.10.1 or later for Windows.
You can find more information about CVE-2019-8756 on the Apple support website. Here are some relevant articles: [link1](https://support.apple.com/en-us/HT210722), [link2](https://support.apple.com/en-us/HT210634), [link3](https://support.apple.com/en-us/HT210604).