CVE-2019-8774: Input Validation
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Parsing a maliciously crafted iBooks file may lead to a persistent denial-of-service.
Other sources
Books. A resource exhaustion issue was addressed with improved input validation.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8748
- CVE-2019-11041
- CVE-2019-11042
- CVE-2019-8706
- CVE-2019-8850
- CVE-2019-8774
- CVE-2019-8753
- CVE-2019-8705
- CVE-2019-8592
- CVE-2019-8741
- CVE-2019-8825
- CVE-2019-8757
- CVE-2019-8736
- CVE-2019-8767
- CVE-2019-8737
- CVE-2019-8776
- CVE-2019-8509
- CVE-2019-8746
- CVE-2018-12152
- CVE-2018-12153
- CVE-2018-12154
- CVE-2019-8759
- CVE-2019-8758
- CVE-2019-8755
- CVE-2019-8703
- CVE-2019-8809
- CVE-2019-8744
- CVE-2019-8717
- CVE-2019-8709
- CVE-2019-8781
- CVE-2019-8749
- CVE-2019-8756
- CVE-2019-8750
- CVE-2019-8799
- CVE-2019-8826
- CVE-2019-8730
- CVE-2019-8772
- CVE-2019-8708
- CVE-2019-8715
- CVE-2019-8855
- CVE-2019-8770
- CVE-2019-8701
- CVE-2019-8761
- CVE-2019-8745
- CVE-2019-8831
- CVE-2019-8769
- CVE-2019-8768
- CVE-2019-8854
- CVE-2019-8747
- CVE-2019-8740
- CVE-2019-8780
- CVE-2019-8901
- CVE-2019-8775
- CVE-2019-8710
- CVE-2019-8743
- CVE-2019-8751
- CVE-2019-8752
- CVE-2019-8763
- CVE-2019-8765
- CVE-2019-8766
- CVE-2019-8773
- CVE-2019-8762
- CVE-2020-9932
Frequently Asked Questions
What is CVE-2019-8774?
CVE-2019-8774 is a resource exhaustion issue in Books that could result in a persistent denial-of-service.
How can this vulnerability be exploited?
This vulnerability can be exploited by parsing a maliciously crafted iBooks file.
What is the severity of CVE-2019-8774?
CVE-2019-8774 has a severity rating of 5.5 (Medium).
Which versions of macOS are affected by CVE-2019-8774?
macOS Catalina 10.15 is affected by CVE-2019-8774.
Which iOS versions are affected by CVE-2019-8774?
iOS 13.1 and iPadOS 13.1 are affected by CVE-2019-8774.
How can I fix CVE-2019-8774?
To fix CVE-2019-8774, update to iOS 13.1 and iPadOS 13.1, or macOS Catalina 10.15.