PT-2019-4180 · Apple · Swift
Published
2019-08-26
·
Updated
2020-11-03
·
CVE-2019-8790
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Swift versions prior to 5.1.1
Endpoint Security Initial Client for Windows (affected versions not specified)
Description
The issue concerns incorrect management of file descriptors in URLSession, potentially leading to inadvertent data disclosure. Another problem is related to the lack of a secure DLL loading mechanism in the Endpoint Security Initial Client for Windows, which could allow an attacker to elevate privileges by running malicious payload.
Recommendations
For Swift versions prior to 5.1.1, update to Swift 5.1.1 to fix the issue with incorrect URLSession file descriptors management logic.
For Endpoint Security Initial Client for Windows, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Swift