CVE Vulnerabilities

CVE-2019-8608

Use After Free

Published: Dec 18, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

Weakness

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory “belongs” to the code that operates on the new pointer.

Affected Software

NameVendorStart VersionEnd Version
IcloudApple*7.12 (excluding)
ItunesApple*12.9.5 (excluding)
SafariApple*12.1.1 (excluding)
Iphone_osApple*12.3 (excluding)
Mac_os_xApple*10.14.5 (excluding)
TvosApple*12.3 (excluding)
Red Hat Enterprise Linux 7RedHatwebkitgtk4-0:2.28.2-2.el7*
Red Hat Enterprise Linux 8RedHataccountsservice-0:0.6.50-7.el8*
Red Hat Enterprise Linux 8RedHatappstream-data-0:8-20190805.el8*
Red Hat Enterprise Linux 8RedHatbaobab-0:3.28.0-2.el8*
Red Hat Enterprise Linux 8RedHatchrome-gnome-shell-0:10.1-6.el8*
Red Hat Enterprise Linux 8RedHatevince-0:3.28.4-3.el8*
Red Hat Enterprise Linux 8RedHatfile-roller-0:3.28.1-2.el8*
Red Hat Enterprise Linux 8RedHatgdk-pixbuf2-0:2.36.12-5.el8*
Red Hat Enterprise Linux 8RedHatgdm-1:3.28.3-22.el8*
Red Hat Enterprise Linux 8RedHatgjs-0:1.56.2-3.el8*
Red Hat Enterprise Linux 8RedHatgnome-control-center-0:3.28.2-5.el8*
Red Hat Enterprise Linux 8RedHatgnome-desktop3-0:3.32.2-1.el8*
Red Hat Enterprise Linux 8RedHatgnome-remote-desktop-0:0.1.6-5.el8*
Red Hat Enterprise Linux 8RedHatgnome-settings-daemon-0:3.32.0-4.el8*
Red Hat Enterprise Linux 8RedHatgnome-shell-0:3.32.2-9.el8*
Red Hat Enterprise Linux 8RedHatgnome-shell-extensions-0:3.32.1-10.el8*
Red Hat Enterprise Linux 8RedHatgnome-software-0:3.30.6-2.el8*
Red Hat Enterprise Linux 8RedHatgnome-tweaks-0:3.28.1-6.el8*
Red Hat Enterprise Linux 8RedHatgsettings-desktop-schemas-0:3.32.0-3.el8*
Red Hat Enterprise Linux 8RedHatgvfs-0:1.36.2-6.el8*
Red Hat Enterprise Linux 8RedHatmozjs60-0:60.9.0-3.el8*
Red Hat Enterprise Linux 8RedHatmutter-0:3.32.2-10.el8*
Red Hat Enterprise Linux 8RedHatnautilus-0:3.28.1-10.el8*
Red Hat Enterprise Linux 8RedHatpango-0:1.42.4-6.el8*
Red Hat Enterprise Linux 8RedHatpidgin-0:2.13.0-5.el8*
Red Hat Enterprise Linux 8RedHatplymouth-0:0.9.3-15.el8*
Red Hat Enterprise Linux 8RedHatSDL-0:1.2.15-35.el8*
Red Hat Enterprise Linux 8RedHatwayland-protocols-0:1.17-1.el8*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:3.22.30-4.el8*
Red Hat Enterprise Linux 8RedHataccountsservice-0:0.6.50-7.el8*
Red Hat Enterprise Linux 8RedHatappstream-data-0:8-20190805.el8*
Red Hat Enterprise Linux 8RedHatbaobab-0:3.28.0-2.el8*
Red Hat Enterprise Linux 8RedHatchrome-gnome-shell-0:10.1-6.el8*
Red Hat Enterprise Linux 8RedHatevince-0:3.28.4-3.el8*
Red Hat Enterprise Linux 8RedHatfile-roller-0:3.28.1-2.el8*
Red Hat Enterprise Linux 8RedHatgdk-pixbuf2-0:2.36.12-5.el8*
Red Hat Enterprise Linux 8RedHatgdm-1:3.28.3-22.el8*
Red Hat Enterprise Linux 8RedHatgjs-0:1.56.2-3.el8*
Red Hat Enterprise Linux 8RedHatgnome-control-center-0:3.28.2-5.el8*
Red Hat Enterprise Linux 8RedHatgnome-desktop3-0:3.32.2-1.el8*
Red Hat Enterprise Linux 8RedHatgnome-remote-desktop-0:0.1.6-5.el8*
Red Hat Enterprise Linux 8RedHatgnome-settings-daemon-0:3.32.0-4.el8*
Red Hat Enterprise Linux 8RedHatgnome-shell-0:3.32.2-9.el8*
Red Hat Enterprise Linux 8RedHatgnome-shell-extensions-0:3.32.1-10.el8*
Red Hat Enterprise Linux 8RedHatgnome-software-0:3.30.6-2.el8*
Red Hat Enterprise Linux 8RedHatgnome-tweaks-0:3.28.1-6.el8*
Red Hat Enterprise Linux 8RedHatgsettings-desktop-schemas-0:3.32.0-3.el8*
Red Hat Enterprise Linux 8RedHatgvfs-0:1.36.2-6.el8*
Red Hat Enterprise Linux 8RedHatmozjs60-0:60.9.0-3.el8*
Red Hat Enterprise Linux 8RedHatmutter-0:3.32.2-10.el8*
Red Hat Enterprise Linux 8RedHatnautilus-0:3.28.1-10.el8*
Red Hat Enterprise Linux 8RedHatpango-0:1.42.4-6.el8*
Red Hat Enterprise Linux 8RedHatpidgin-0:2.13.0-5.el8*
Red Hat Enterprise Linux 8RedHatplymouth-0:0.9.3-15.el8*
Red Hat Enterprise Linux 8RedHatSDL-0:1.2.15-35.el8*
Red Hat Enterprise Linux 8RedHatwayland-protocols-0:1.17-1.el8*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:3.22.30-4.el8*
QtwebkitUbuntueoan*
Qtwebkit-opensource-srcUbuntubionic*
Qtwebkit-opensource-srcUbuntucosmic*
Qtwebkit-opensource-srcUbuntudevel*
Qtwebkit-opensource-srcUbuntudisco*
Qtwebkit-opensource-srcUbuntueoan*
Qtwebkit-opensource-srcUbuntuesm-apps/bionic*
Qtwebkit-opensource-srcUbuntuesm-apps/focal*
Qtwebkit-opensource-srcUbuntuesm-apps/jammy*
Qtwebkit-opensource-srcUbuntuesm-apps/noble*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntufocal*
Qtwebkit-opensource-srcUbuntugroovy*
Qtwebkit-opensource-srcUbuntuhirsute*
Qtwebkit-opensource-srcUbuntuimpish*
Qtwebkit-opensource-srcUbuntujammy*
Qtwebkit-opensource-srcUbuntukinetic*
Qtwebkit-opensource-srcUbuntulunar*
Qtwebkit-opensource-srcUbuntumantic*
Qtwebkit-opensource-srcUbuntunoble*
Qtwebkit-opensource-srcUbuntutrusty*
Qtwebkit-opensource-srcUbuntuupstream*
Qtwebkit-opensource-srcUbuntuxenial*
Qtwebkit-sourceUbuntubionic*
Qtwebkit-sourceUbuntucosmic*
Qtwebkit-sourceUbuntudisco*
Qtwebkit-sourceUbuntuesm-apps/bionic*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Qtwebkit-sourceUbuntutrusty*
Qtwebkit-sourceUbuntuxenial*
Webkit2gtkUbuntubionic*
Webkit2gtkUbuntucosmic*
Webkit2gtkUbuntuesm-infra/bionic*
Webkit2gtkUbuntuesm-infra/xenial*
Webkit2gtkUbuntuupstream*
Webkit2gtkUbuntuxenial*
WebkitgtkUbuntubionic*
WebkitgtkUbuntucosmic*
WebkitgtkUbuntuesm-apps/bionic*
WebkitgtkUbuntuesm-apps/xenial*
WebkitgtkUbuntutrusty*
WebkitgtkUbuntuxenial*

Potential Mitigations

References