CVE-2019-8724

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
18/12/2019
Last modified:
22/12/2019

Description

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:* 11.0 (excluding)


References to Advisories, Solutions, and Tools