An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. Parsing a maliciously crafted office document may lead to an unexpected application termination or arbitrary code execution.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://support.apple.com/HT210353 | vendor advisory |
https://support.apple.com/HT210346 | vendor advisory |
https://support.apple.com/HT210348 | vendor advisory |
https://support.apple.com/HT210351 | vendor advisory |