webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
Published Dec 18, 2019
8.8
HIGHCVSS 3.1
EPSS 1.96%
Description
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected products
-
Affected
- ≥ unspecified, < Safari 12.1.1
-
Affected
- ≥ unspecified, < iCloud for Windows 7.12
-
Affected
- ≥ unspecified, < iOS 12.3
-
Affected
- ≥ unspecified, < iTunes for Windows 12.9.5
-
Affected
- ≥ unspecified, < macOS Mojave 10.14.5
-
Affected
- ≥ unspecified, < tvOS 12.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apple | Safari | unknown | Affected
|
| Apple | iCloud for Windows | unknown | Affected
|
| Apple | iOS | unknown | Affected
|
| Apple | iTunes for Windows | unknown | Affected
|
| Apple | macOS | unknown | Affected
|
| Apple | tvOS | unknown | Affected
|
No data.
Red Hat Enterprise Linux 7
webkitgtk4-0:2.28.2-2.el7
Fixed · RHSA-2020:4035
Red Hat Enterprise Linux 8
SDL-0:1.2.15-35.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
SDL-0:1.2.15-35.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
accountsservice-0:0.6.50-7.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
accountsservice-0:0.6.50-7.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
appstream-data-0:8-20190805.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
appstream-data-0:8-20190805.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
baobab-0:3.28.0-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
baobab-0:3.28.0-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
chrome-gnome-shell-0:10.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
chrome-gnome-shell-0:10.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
evince-0:3.28.4-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
evince-0:3.28.4-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
file-roller-0:3.28.1-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
file-roller-0:3.28.1-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdm-1:3.28.3-22.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdm-1:3.28.3-22.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gjs-0:1.56.2-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gjs-0:1.56.2-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-control-center-0:3.28.2-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-control-center-0:3.28.2-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-desktop3-0:3.32.2-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-desktop3-0:3.32.2-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-remote-desktop-0:0.1.6-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-remote-desktop-0:0.1.6-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-settings-daemon-0:3.32.0-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-settings-daemon-0:3.32.0-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-0:3.32.2-9.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-0:3.32.2-9.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-extensions-0:3.32.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-extensions-0:3.32.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-software-0:3.30.6-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-software-0:3.30.6-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-tweaks-0:3.28.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-tweaks-0:3.28.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gsettings-desktop-schemas-0:3.32.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gsettings-desktop-schemas-0:3.32.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gtk3-0:3.22.30-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gtk3-0:3.22.30-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gvfs-0:1.36.2-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gvfs-0:1.36.2-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mozjs60-0:60.9.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mozjs60-0:60.9.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mutter-0:3.32.2-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mutter-0:3.32.2-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
nautilus-0:3.28.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
nautilus-0:3.28.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pango-0:1.42.4-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pango-0:1.42.4-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pidgin-0:2.13.0-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pidgin-0:2.13.0-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
plymouth-0:0.9.3-15.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
plymouth-0:0.9.3-15.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
wayland-protocols-0:1.17-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
wayland-protocols-0:1.17-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.24.3-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.24.3-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | webkitgtk4-0:2.28.2-2.el7 | Fixed | RHSA-2020:4035 |
| Red Hat Enterprise Linux 8 | SDL-0:1.2.15-35.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | SDL-0:1.2.15-35.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | accountsservice-0:0.6.50-7.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | accountsservice-0:0.6.50-7.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | appstream-data-0:8-20190805.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | appstream-data-0:8-20190805.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | baobab-0:3.28.0-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | baobab-0:3.28.0-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | chrome-gnome-shell-0:10.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | chrome-gnome-shell-0:10.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | evince-0:3.28.4-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | evince-0:3.28.4-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | file-roller-0:3.28.1-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | file-roller-0:3.28.1-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdm-1:3.28.3-22.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdm-1:3.28.3-22.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gjs-0:1.56.2-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gjs-0:1.56.2-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-control-center-0:3.28.2-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-control-center-0:3.28.2-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-desktop3-0:3.32.2-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-desktop3-0:3.32.2-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-remote-desktop-0:0.1.6-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-remote-desktop-0:0.1.6-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-settings-daemon-0:3.32.0-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-settings-daemon-0:3.32.0-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-0:3.32.2-9.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-0:3.32.2-9.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-extensions-0:3.32.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-extensions-0:3.32.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-software-0:3.30.6-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-software-0:3.30.6-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-tweaks-0:3.28.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-tweaks-0:3.28.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gsettings-desktop-schemas-0:3.32.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gsettings-desktop-schemas-0:3.32.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gtk3-0:3.22.30-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gtk3-0:3.22.30-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gvfs-0:1.36.2-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gvfs-0:1.36.2-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mozjs60-0:60.9.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mozjs60-0:60.9.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mutter-0:3.32.2-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mutter-0:3.32.2-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | nautilus-0:3.28.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | nautilus-0:3.28.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pango-0:1.42.4-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pango-0:1.42.4-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pidgin-0:2.13.0-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pidgin-0:2.13.0-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | plymouth-0:0.9.3-15.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | plymouth-0:0.9.3-15.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | wayland-protocols-0:1.17-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | wayland-protocols-0:1.17-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.24.3-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.24.3-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2019-8594 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1876891 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-17984 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-8594
- https://support.apple.com/HT210118 x_refsource_MISCVendor Advisory
- https://support.apple.com/HT210119 x_refsource_MISCVendor Advisory
- https://support.apple.com/HT210120 x_refsource_MISCVendor Advisory
- https://support.apple.com/HT210123 x_refsource_MISCVendor Advisory
- https://support.apple.com/HT210124 x_refsource_MISCVendor Advisory
- https://support.apple.com/HT210125 x_refsource_MISCVendor Advisory
- https://support.apple.com/HT210212 x_refsource_MISCVendor Advisory
- https://webkitgtk.org/security/WSA-2019-0003.html
- https://www.cve.org/CVERecord?id=CVE-2019-8594
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-8594 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1876891 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-17984 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-8594 | ||
| https://support.apple.com/HT210118 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/HT210119 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/HT210120 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/HT210123 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/HT210124 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/HT210125 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/HT210212 | x_refsource_MISCVendor Advisory | |
| https://webkitgtk.org/security/WSA-2019-0003.html | ||
| https://www.cve.org/CVERecord?id=CVE-2019-8594 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data