CVE-2019-8582

Description

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.296

Associated Vulnerability

VulnerabilityOS Platform
CVE-2019-8582 fixed in iCloud (7.12.0.14)Windows
CVE-2019-8582 fixed in Apple iTunes (12.9.5.7)Windows
CVE-2019-8582 fixed in Apple iTunes (X64) (12.9.5.7)Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 12.9.4Windows
Multiple Vulnerabilities are affected in Apple iTunes 12.9.4Windows
Multiple vulnerabilities are fixed in macOS Mojave 10.14.5 Combo UpdateMac
Multiple vulnerabilities are fixed in macOS Mojave 10.14.5Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309928iCloud (7.12.0.14)
PATCH-309936Apple iTunes (12.9.5.7)
PATCH-309938Apple iTunes (X64) (12.9.5.7)
PATCH-602005macOS Mojave 10.14.6 Combo Update
PATCH-602004macOS Mojave 10.14.6

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234