lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 10 Dec 2019 15:55:21 -0800
From: Apple Product Security via Fulldisclosure <fulldisclosure@...lists.org>
To: security-announce@...ts.apple.com
Subject: [FD] APPLE-SA-2019-12-10-4 watchOS 5.3.4

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2019-12-10-4 watchOS 5.3.4

watchOS 5.3.4 is now available and addresses the following:

FaceTime
Available for: Apple Watch Series 1, Apple Watch Series 2, Apple
Watch Series 3, and Apple Watch Series 4 when paired to a device with
iOS 12 installed
Impact: Processing malicious video via FaceTime may lead to arbitrary
code execution
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2019-8830: Natalie Silvanovich of Google Project Zero

Installation note:

Instructions on how to update your Apple Watch software are
available at https://support.apple.com/kb/HT204641

To check the version on your Apple Watch, open the Apple Watch app
on your iPhone and select "My Watch > General > About".

Alternatively, on your watch, select "My Watch > General > About".

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEM5FaaFRjww9EJgvRBz4uGe3y0M0FAl3wFsIACgkQBz4uGe3y
0M081g//diPPIlbOXb2t9E8BZQugpj2XJf36gvejgReUIbrPG30wxitkf+hruSfI
tDZfrvFmyeudiKJ47PpkamQ8CfnppaPm6FCOr2D4kQgCMOy2Ac+hxTbKjHPDjzvi
0gY9WKTdwfZVtDuzT9utQY82oUMe7kKohCksbdKV4VByPeNfDO4o/Pnwcq/byrDb
GXyBg/yiunWLxeqSqJEYGcrh0DYIhjFAaPH9EU757WBwsKYd6H+aF7AvMcVRuY/p
Nm08DBZG5PU/ctZFDMWluIwaqsBj/t6DWtEwgvYrsJP9zVKiH47WpeH0rG9wHvM2
z7cY+h6cyNL7xmY2/lSyZIklOkAF3drZbB89kCb+ysfA92U0D1YyZMeC1ZNoEYYW
awcZCBavTxj/NeF6g6CNiBmVK1h2C3nSNvV6zbsmgQ7nhZgYH24g9ZppAy6/HMhq
UK7mspj43HjSo8LIc99wHGxXc5wuc25YGqVgbzd8Yw1kbmDzRdWWJ83G1H+cAuEx
59R48FD8hpmayFCDD5OWAnf1tJXYth+Rp57rs2mWgSDdFJ3vk8yd0JaSumiLu6/N
Pwm7vg7tVe9Bmfp9ipFJ9xZz/EQ5eaZe6FlwmxocjxFCkBsXHnfMq9ecr4E4oyD2
PEqayT+ZWZXbmYKvWzOCX/5L7e5HwVLx8GxGvUwYUyLBX1JEqt0=
=Wdm1
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists