CVE-2019-8626: Input Validation
Published May 13, 2019
·Updated
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
Other sources
Mail. An input validation issue was addressed with improved input validation.
Credit
natashenka(Google Project Zero)
Affected Software
4 affected componentsFixes available
Apple WatchOS<5.2.1
5.2.1
Apple iOS<12.3
12.3
Apple iPhone OS<12.3
Apple WatchOS<5.2.1
Event History
Dec 18, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8593
- CVE-2019-8585
- CVE-2019-8592
- CVE-2019-8560
- CVE-2019-8605
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8626
- CVE-2019-8613
- CVE-2019-8664
- CVE-2019-8573
- CVE-2019-8568
- CVE-2019-8637
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8574
- CVE-2019-8607
- CVE-2019-8583
- CVE-2019-8601
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8612
- CVE-2019-8620
- CVE-2019-2102
- CVE-2019-8582
- CVE-2019-8633
- CVE-2019-8599
- CVE-2019-8631
- CVE-2019-8617
- CVE-2019-8630
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8628
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8626.
2
What is the severity of CVE-2019-8626?
The severity of CVE-2019-8626 is medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2019-8626?
iOS versions up to but excluding 12.3, and watchOS versions up to but excluding 5.2.1 are affected by CVE-2019-8626.
4
How can the vulnerability be fixed?
To fix CVE-2019-8626, update to iOS 12.3 or later, or update to watchOS 5.2.1 or later.
5
What is the impact of exploiting CVE-2019-8626?
Exploiting CVE-2019-8626 can lead to a denial of service by processing a maliciously crafted message.