CVE-2019-8585: Input Validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. Processing a maliciously crafted movie file may lead to arbitrary code execution.
Other sources
CoreAudio. An out-of-bounds read was addressed with improved input validation.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8593
- CVE-2019-2102
- CVE-2019-8592
- CVE-2019-8585
- CVE-2019-8582
- CVE-2019-8560
- CVE-2019-8633
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8631
- CVE-2019-8568
- CVE-2019-8637
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8574
- CVE-2019-8607
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8583
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8601
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8628
- CVE-2019-8612
- CVE-2019-8620
- CVE-2019-8603
- CVE-2019-8635
- CVE-2019-8590
- CVE-2019-8640
- CVE-2019-8589
- CVE-2019-8634
- CVE-2019-8616
- CVE-2019-8629
- CVE-2018-4456
- CVE-2019-8606
- CVE-2019-8525
- CVE-2019-8547
- CVE-2019-8573
- CVE-2018-12126
- CVE-2018-12127
- CVE-2018-12130
- CVE-2019-11091
- CVE-2019-8604
- CVE-2019-8569
- CVE-2019-8605
- CVE-2019-8626
- CVE-2019-8613
- CVE-2019-8664
- CVE-2019-8599
- CVE-2019-8617
- CVE-2019-8630
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8585.
What is the severity level of CVE-2019-8585?
The severity level of CVE-2019-8585 is high.
How does CVE-2019-8585 work?
CVE-2019-8585 is an out-of-bounds read vulnerability that is triggered when processing a maliciously crafted movie file, which may lead to arbitrary code execution.
Which Apple products are affected by CVE-2019-8585?
The affected Apple products include macOS Mojave (up to version 10.14.5), iOS (up to version 12.3), tvOS (up to version 12.3), and watchOS (up to version 5.2.1).
How can I fix CVE-2019-8585?
To fix CVE-2019-8585, it is recommended to update to iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, or watchOS 5.2.1, depending on the affected product.