Buffer overflow - CVE-2019-8844

 

Buffer overflow - CVE-2019-8844

Published: October 27, 2020 / Updated: November 1, 2020


Vulnerability identifier: #VU48063
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8844
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.


Affected software

Debian Linux
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Fedora
Service Telemetry Framework
webkit2gtk (Alpine package)
gnome-remote-desktop (Red Hat package)
pipewire0.2 (Red Hat package)
pipewire (Red Hat package)
webrtc-audio-processing (Red Hat package)
dleyna-renderer (Red Hat package)
LibRaw (Red Hat package)
vte291 (Red Hat package)
PackageKit (Red Hat package)
xdg-desktop-portal-gtk (Red Hat package)
xdg-desktop-portal (Red Hat package)
frei0r-plugins (Red Hat package)
potrace (Red Hat package)
gtk-doc (Red Hat package)
gvfs (Red Hat package)
tracker (Red Hat package)
webkit2gtk
webkit2gtk3
webkit2gtk (Debian package)
net-libs/webkit-gtk
webkit2gtk3 (Red Hat package)
libsoup (Red Hat package)
gtk3 (Red Hat package)
gnome-photos (Red Hat package)
gnome-session (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
pygobject3 (Red Hat package)
gnome-terminal (Red Hat package)
gdm (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2019-8844

Install update from vendor's website.

webkit2gtk (Alpine package) - addressed in versions 2.28.0-r0, 2.28.0-r1
Quay - update to 3.3.3
gnome-remote-desktop (Red Hat package) - update to 0.1.8-3.el8
pipewire0.2 (Red Hat package) - update to 0.2.7-6.el8
pipewire (Red Hat package) - update to 0.3.6-1.el8
webrtc-audio-processing (Red Hat package) - update to 0.3-9.el8
dleyna-renderer (Red Hat package) - update to 0.6.0-3.el8
LibRaw (Red Hat package) - update to 0.19.5-2.el8
vte291 (Red Hat package) - update to 0.52.4-2.el8
PackageKit (Red Hat package) - update to 1.1.12-6.el8
xdg-desktop-portal-gtk (Red Hat package) - update to 1.6.0-1.el8
xdg-desktop-portal (Red Hat package) - update to 1.6.0-2.el8
frei0r-plugins (Red Hat package) - update to 1.6.1-7.el8
potrace (Red Hat package) - update to 1.15-3.el8
gtk-doc (Red Hat package) - update to 1.28-2.el8
gvfs (Red Hat package) - update to 1.36.2-10.el8
tracker (Red Hat package) - update to 2.1.5-2.el8
webkit2gtk - update to 2.26.3-1
webkit2gtk3 - addressed in versions 2.26.3-1.fc30, 2.26.3-1.fc31
webkit2gtk (Debian package) - update to 2.26.3-1~deb10u1
net-libs/webkit-gtk - update to 2.26.4
webkit2gtk3 (Red Hat package) - update to 2.28.4-1.el8
libsoup (Red Hat package) - update to 2.62.3-2.el8
gtk3 (Red Hat package) - update to 3.22.30-6.el8
gnome-photos (Red Hat package) - update to 3.28.1-3.el8
gnome-session (Red Hat package) - update to 3.28.1-10.el8
nautilus (Red Hat package) - update to 3.28.1-14.el8
gnome-control-center (Red Hat package) - update to 3.28.2-22.el8
pygobject3 (Red Hat package) - update to 3.28.3-2.el8
gnome-terminal (Red Hat package) - update to 3.28.3-2.el8
gdm (Red Hat package) - update to 3.28.3-34.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-5.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-11.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-11.el8
gnome-shell (Red Hat package) - update to 3.32.2-20.el8
mutter (Red Hat package) - update to 3.32.2-48.el8

External References

Related Security Bulletins