CVE-2019-8802: Input Validation
Published Oct 29, 2019
·Updated
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.
Other sources
manpages. A validation issue was addressed with improved logic.
Credit
Csaba Fitzl@@theevilbit
Affected Software
2 affected componentsFixes available
apple macOS Catalina<10.15.1
10.15.1
Apple iOS and macOS<10.15.1
Event History
Dec 18, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8787
- CVE-2019-8796
- CVE-2019-8748
- CVE-2019-11041
- CVE-2019-11042
- CVE-2019-8824
- CVE-2019-8803
- CVE-2019-8817
- CVE-2019-8716
- CVE-2019-8788
- CVE-2019-8706
- CVE-2019-8785
- CVE-2019-8797
- CVE-2019-8850
- CVE-2019-8789
- CVE-2017-7152
- CVE-2019-8592
- CVE-2019-8705
- CVE-2019-8825
- CVE-2019-8736
- CVE-2019-8767
- CVE-2019-8737
- CVE-2019-8509
- CVE-2019-8798
- CVE-2019-8746
- CVE-2018-12152
- CVE-2018-12153
- CVE-2018-12154
- CVE-2019-8784
- CVE-2019-8807
- CVE-2019-8759
- CVE-2019-8801
- CVE-2019-8709
- CVE-2019-8794
- CVE-2019-8717
- CVE-2019-8786
- CVE-2019-8744
- CVE-2019-8829
- CVE-2019-8749
- CVE-2019-8756
- CVE-2019-8750
- CVE-2019-8802
- CVE-2019-8772
- CVE-2019-8708
- CVE-2019-8715
- CVE-2019-8858
- CVE-2019-8805
- CVE-2019-8754
- CVE-2019-8745
- CVE-2019-8831
- CVE-2019-8761
- CVE-2019-15126
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8802.
2
What is the severity of CVE-2019-8802?
The severity of CVE-2019-8802 is critical.
3
How does CVE-2019-8802 impact macOS Catalina?
CVE-2019-8802 allows a malicious application to gain root privileges on macOS Catalina.
4
Which versions of macOS Catalina are affected by CVE-2019-8802?
Versions of macOS Catalina up to and excluding 10.15.1 are affected by CVE-2019-8802.
5
How can I fix CVE-2019-8802?
CVE-2019-8802 is fixed in macOS Catalina 10.15.1, so updating to that version will resolve the issue.