CVE-2019-8840: High severity apple xcode vulnerability
Published Dec 10, 2019
·Updated
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges.
Other sources
ld64. An out-of-bounds read was addressed with improved bounds checking.
Credit
Pan ZhenPeng@@Peterpan0927(Qihoo 360 Nirvan Team)
Affected Software
2 affected componentsFixes available
Apple Xcode<11.3
11.3
Apple Xcode<11.3
Event History
Oct 27, 2020
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-8840.
2
What is the severity rating of CVE-2019-8840?
CVE-2019-8840 has a severity rating of 8.8 (high).
3
What is the affected software for CVE-2019-8840?
The affected software is Apple Xcode version up to exclusive 11.3.
4
How can I fix CVE-2019-8840?
The vulnerability is fixed in Xcode 11.3, so updating to that version or later will resolve the issue.
5
Can arbitrary code execution occur with user privileges?
Yes, compiling with untrusted sources may lead to arbitrary code execution with user privileges.