file. Multiple issues were addressed by updating to version 5.31.
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "PCRE" product. Versions before 8.40 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Remote Management. A permissions issue existed in Remote Management. This issue was addressed through improved permission validation.
Heimdal. A memory corruption issue was addressed with improved memory handling.
MediaRemote. An access issue was addressed with additional sandbox restrictions.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Kernel. Multiple memory corruption issues were addressed with improved memory handling.
Grand Central Dispatch. An issue existed in parsing entitlement plists. This issue was addressed with improved input validation.
AMD. An input validation issue existed in the kernel. This issue was addressed with improved input validation.
AppleGraphicsControl. A buffer overflow was addressed with improved bounds checking.
AppleGraphicsPowerManagement. A buffer overflow was addressed with improved size validation.
Security. A logic issue was addressed with improved restrictions.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
APFS. A memory corruption issue was addressed with improved memory handling.
An integer overflow during the parsing of XML using the Expat library.
802.1X. A logic issue was addressed with improved state management.
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.
In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A remote attacker may be able to cause an out-of-bounds read or write that may cause the kernel to attempt to access an unmapped page and subsequently panic.
Kernel. An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation.
SQLite. A memory corruption issue was addressed with improved input validation.
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
FaceTime. A memory corruption issue was addressed with improved input validation.
Carbon Core. A use after free issue was addressed with improved memory management.
Quick Look. This issue was addressed with improved checks.
tcpdump. Multiple issues were addressed by updating to version 4.9.2.
tcpdump. Multiple issues were addressed by updating to version 4.9.2.