First published: Wed Dec 18 2019(Updated: )
The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
SwiftNIO | <2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8849 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2019-8849, upgrade to SwiftNIO SSL version 2.4.1 or later.
CVE-2019-8849 affects SwiftNIO applications that use TLS.
Exploiting CVE-2019-8849 could allow an attacker to execute arbitrary code within a vulnerable application.
There are no known workarounds for CVE-2019-8849, so upgrading is strongly recommended.