CVE-2019-8607: Input Validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the disclosure of process memory.
Other sources
WebKit. An out-of-bounds read was addressed with improved input validation.
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8607
Processing maliciously crafted web content may result in the disclosure of process memory. An out-of-bounds read was addressed with improved input validation.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8593
- CVE-2019-2102
- CVE-2019-8592
- CVE-2019-8585
- CVE-2019-8582
- CVE-2019-8560
- CVE-2019-8633
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8631
- CVE-2019-8568
- CVE-2019-8637
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8574
- CVE-2019-8607
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8583
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8601
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8628
- CVE-2019-8612
- CVE-2019-8620
- CVE-2019-8603
- CVE-2019-8635
- CVE-2019-8590
- CVE-2019-8640
- CVE-2019-8589
- CVE-2019-8634
- CVE-2019-8616
- CVE-2019-8629
- CVE-2018-4456
- CVE-2019-8606
- CVE-2019-8525
- CVE-2019-8547
- CVE-2019-8573
- CVE-2018-12126
- CVE-2018-12127
- CVE-2018-12130
- CVE-2019-11091
- CVE-2019-8604
- CVE-2019-8569
- CVE-2019-8605
- CVE-2019-8626
- CVE-2019-8613
- CVE-2019-8664
- CVE-2019-8599
- CVE-2019-8617
- CVE-2019-8630
Frequently Asked Questions
What is CVE-2019-8607?
CVE-2019-8607 is a vulnerability in WebKit that allows an attacker to read out-of-bounds memory, potentially resulting in the disclosure of process memory.
Which software versions are affected by CVE-2019-8607?
CVE-2019-8607 affects iOS up to version 12.3, macOS Mojave up to version 10.14.5, tvOS up to version 12.3, watchOS up to version 5.2.1, Safari up to version 12.1.1, iTunes for Windows up to version 12.9.5, and iCloud for Windows up to version 7.12.
How can I fix CVE-2019-8607?
To fix CVE-2019-8607, update your software to the following versions: iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, and iCloud for Windows 7.12.
What is the severity of CVE-2019-8607?
CVE-2019-8607 has a severity rating of 6.5 (Medium).
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-8607?
The Common Weakness Enumeration (CWE) IDs for CVE-2019-8607 are CWE-20 (Improper Input Validation) and CWE-125 (Out-of-bounds Read).