CVE-2019-8640: Input Validation
Archive Utility. A logic issue was addressed with improved validation.
Other sources
A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra. A sandboxed process may be able to circumvent sandbox restrictions.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8603
- CVE-2019-8635
- CVE-2019-8590
- CVE-2019-8640
- CVE-2019-2102
- CVE-2019-8592
- CVE-2019-8585
- CVE-2019-8582
- CVE-2019-8589
- CVE-2019-8560
- CVE-2019-8634
- CVE-2019-8616
- CVE-2019-8629
- CVE-2018-4456
- CVE-2019-8606
- CVE-2019-8633
- CVE-2019-8525
- CVE-2019-8547
- CVE-2019-8576
- CVE-2019-8591
- CVE-2019-8573
- CVE-2019-8631
- CVE-2018-12126
- CVE-2018-12127
- CVE-2018-12130
- CVE-2019-11091
- CVE-2019-8604
- CVE-2019-8577
- CVE-2019-8600
- CVE-2019-8598
- CVE-2019-8602
- CVE-2019-8568
- CVE-2019-8574
- CVE-2019-8569
- CVE-2019-6237
- CVE-2019-8571
- CVE-2019-8583
- CVE-2019-8584
- CVE-2019-8586
- CVE-2019-8587
- CVE-2019-8594
- CVE-2019-8595
- CVE-2019-8596
- CVE-2019-8597
- CVE-2019-8601
- CVE-2019-8608
- CVE-2019-8609
- CVE-2019-8610
- CVE-2019-8611
- CVE-2019-8615
- CVE-2019-8619
- CVE-2019-8622
- CVE-2019-8623
- CVE-2019-8628
- CVE-2019-8607
- CVE-2019-8612
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8640.
What is the severity of CVE-2019-8640?
The severity of CVE-2019-8640 is high with a CVSS score of 7.5.
What is the affected software?
The affected software includes macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, and Security Update 2019-003 Sierra.
How can the vulnerability be fixed?
The vulnerability can be fixed by updating to macOS Mojave 10.14.5, or applying Security Update 2019-003 for High Sierra or Sierra.
What is the description of CVE-2019-8640?
CVE-2019-8640 is a logic issue in Archive Utility that was addressed with improved validation. A sandboxed process may be able to circumvent sandbox restrictions.