Buffer overflow - CVE-2019-8688

 

Buffer overflow - CVE-2019-8688

Published: December 18, 2019 / Updated: August 4, 2020


Vulnerability identifier: #VU33360
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8688
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.


Affected software

Arch Linux
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud
Red Hat Enterprise Linux for IBM z Systems
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Opensuse
webkit2gtk (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
webkit2gtk3 (Red Hat package)
libjavascriptcoregtk-4_0-18
libjavascriptcoregtk-4_0-18-debuginfo
libwebkit2gtk-4_0-37
libwebkit2gtk-4_0-37-debuginfo
typelib-1_0-JavaScriptCore-4_0
typelib-1_0-WebKit2-4_0
typelib-1_0-WebKit2WebExtension-4_0
webkit2gtk-4_0-injected-bundles
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk3-debugsource
libwebkit2gtk3-lang
webkit2gtk3-devel

How to mitigate CVE-2019-8688

Install update from vendor's website.

webkit2gtk (Alpine package) - update to 2.26.2-r0
webkit2gtk3 (Red Hat package) - update to 2.24.4-2.el8_1
libjavascriptcoregtk-4_0-18 - update to 2.34.3-2.82.1
libjavascriptcoregtk-4_0-18-debuginfo - update to 2.34.3-2.82.1
libwebkit2gtk-4_0-37 - update to 2.34.3-2.82.1
libwebkit2gtk-4_0-37-debuginfo - update to 2.34.3-2.82.1
typelib-1_0-JavaScriptCore-4_0 - update to 2.34.3-2.82.1
typelib-1_0-WebKit2-4_0 - update to 2.34.3-2.82.1
typelib-1_0-WebKit2WebExtension-4_0 - update to 2.34.3-2.82.1
webkit2gtk-4_0-injected-bundles - update to 2.34.3-2.82.1
webkit2gtk-4_0-injected-bundles-debuginfo - update to 2.34.3-2.82.1
webkit2gtk3-debugsource - update to 2.34.3-2.82.1
libwebkit2gtk3-lang - update to 2.34.3-2.82.1
webkit2gtk3-devel - update to 2.34.3-2.82.1

External References

Related Security Bulletins