{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos8.4els/vex/2019/cve-2019-8608-els_os-centos8_4els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-04-20T16:10:13Z",
      "generator": {
        "date": "2026-04-20T16:10:13Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2019-8608-ELS_OS-CENTOS8.4ELS",
      "initial_release_date": "2019-12-18T18:15:00Z",
      "revision_history": [
        {
          "date": "2019-12-18T18:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-14T11:44:33Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-04-20T16:10:13Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2019-8608"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8.4",
                "product": {
                  "name": "Community Enterprise Operating System 8.4",
                  "product_id": "CentOS-8.4",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8.4:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "file-roller-0:3.28.1-3.el8.4.x86_64",
                "product": {
                  "name": "file-roller-0:3.28.1-3.el8.4.x86_64",
                  "product_id": "file-roller-0:3.28.1-3.el8.4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/file-roller@3.28.1-3.el8.4?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
                "product": {
                  "name": "file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
                  "product_id": "file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file-roller@3.28.1-3.el8.4.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8.4",
          "product_id": "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64"
        },
        "product_reference": "file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-8.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-roller-0:3.28.1-3.el8.4.x86_64 as a component of Community Enterprise Operating System 8.4",
          "product_id": "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.x86_64"
        },
        "product_reference": "file-roller-0:3.28.1-3.el8.4.x86_64",
        "relates_to_product_reference": "CentOS-8.4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2019-8608",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
          "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2019-8608"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210118",
          "url": "https://support.apple.com/HT210118"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210119",
          "url": "https://support.apple.com/HT210119"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210120",
          "url": "https://support.apple.com/HT210120"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210123",
          "url": "https://support.apple.com/HT210123"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210124",
          "url": "https://support.apple.com/HT210124"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210125",
          "url": "https://support.apple.com/HT210125"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/HT210212",
          "url": "https://support.apple.com/HT210212"
        }
      ],
      "release_date": "2019-12-18T18:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "CVE-2019-8608 is a WebKit client-side issue in Apple platforms and Apple client software on Windows (Safari, iTunes, iCloud), not a vulnerability in Linux server components, so the vulnerable code path is absent on managed Linux VMs/servers. Exploitation also requires users to actively process malicious web content in a graphical browser, which is not part of typical server or headless workload operation. Given the platform mismatch and required user interaction, this CVE can be safely deprioritized for enterprise Linux server environments.",
          "product_ids": [
            "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
            "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.tuxcare.els1.x86_64",
            "CentOS-8.4:file-roller-0:3.28.1-3.el8.4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}