cve/2019/CVE-2019-8605.md

35 lines
1.9 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-8605](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8605)
![](https://img.shields.io/static/v1?label=Product&message=iOS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=macOS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=tvOS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=watchOS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20iOS%2012.3%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20macOS%20Mojave%2010.14.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20tvOS%2012.3%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Version&message=%3C%20watchOS%205.2.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=A%20malicious%20application%20may%20be%20able%20to%20execute%20arbitrary%20code%20with%20system%20privileges&color=brighgreen)
### Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/1nteger-c/CVE-2019-8605
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Embodimentgeniuslm3/glowing-adventure
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/WRFan/jailbreak10.3.3
- https://github.com/alphaSeclab/sec-daily-2019
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/fengjixuchui/iOS-macOS-Vul-Analysis-Articles
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/jsherman212/used_sock
- https://github.com/staturnzz/socket