CVE-2019-8608: Use After Free
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8608
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8593
- CVE-2019-2102
- CVE-2019-8592
- CVE-2019-8585
- CVE-2019-8582
- CVE-2019-8560
- CVE-2019-8633
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8631
- CVE-2019-8568
- CVE-2019-8637
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8574
- CVE-2019-8607
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8583
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8601
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8628
- CVE-2019-8612
- CVE-2019-8620
- CVE-2019-8603
- CVE-2019-8635
- CVE-2019-8590
- CVE-2019-8640
- CVE-2019-8589
- CVE-2019-8634
- CVE-2019-8616
- CVE-2019-8629
- CVE-2018-4456
- CVE-2019-8606
- CVE-2019-8525
- CVE-2019-8547
- CVE-2019-8573
- CVE-2018-12126
- CVE-2018-12127
- CVE-2018-12130
- CVE-2019-11091
- CVE-2019-8604
- CVE-2019-8569
- CVE-2019-8599
- CVE-2019-8626
- CVE-2019-8613
- CVE-2019-8664
- CVE-2019-8617
- CVE-2019-8630
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2019-8608.
What is the severity of CVE-2019-8608?
The severity of CVE-2019-8608 is medium with a CVSS score of 6.3.
Which products and versions are affected by CVE-2019-8608?
macOS Mojave 10.14.5, iOS 12.3, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12, and WebKitGTK 2.24.1 are affected by CVE-2019-8608.
How can the vulnerability CVE-2019-8608 be fixed?
The vulnerability CVE-2019-8608 can be fixed by updating to the following versions: iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, and iCloud for Windows 7.12.
What are the references for CVE-2019-8608?
The references for CVE-2019-8608 are: [Apple Support - HT210119](https://support.apple.com/en-us/HT210119), [Apple Support - HT210118](https://support.apple.com/en-us/HT210118), [Apple Support - HT210120](https://support.apple.com/en-us/HT210120).