CVE-2019-8602 Information
Feb 14, 2021
cve
Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3 macOS Mojave 10.14.5 tvOS 12.3 watchOS 5.2.1 iTunes for Windows 12.9.5 iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://research.checkpoint.com/2019/select-code_execution-from-using-sqlite/ https://support.apple.com/HT210118 https://support.apple.com/HT210119 https://support.apple.com/HT210120 https://support.apple.com/HT210122 https://support.apple.com/HT210124 https://support.apple.com/HT210125 https://support.apple.com/HT210212
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: