First published: Thu Sep 24 2020(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
Credit: Aleksandar Nikolic Cisco TalosAleksandar Nikolic Cisco TalosAleksandar Nikolic Cisco TalosAleksandar Nikolic Cisco TalosAleksandar Nikolic Cisco Talos product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.0.1 | 11.0.1 |
tvOS | <14.2 | 14.2 |
macOS Catalina | <10.15.7 | 10.15.7 |
macOS High Sierra | ||
macOS Mojave | ||
Apple iOS, iPadOS, and watchOS | <14.2 | 14.2 |
Apple iOS, iPadOS, and watchOS | <14.2 | 14.2 |
Apple iOS, iPadOS, and watchOS | <14.2 | |
iOS | <14.2 | |
Apple iOS and macOS | <10.13.6 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | >=11.0.0<11.0.1 | |
Apple iOS and macOS | =10.13.6 | |
Apple iOS and macOS | =10.13.6-security_update_2018-002 | |
Apple iOS and macOS | =10.13.6-security_update_2018-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-001 | |
Apple iOS and macOS | =10.13.6-security_update_2019-002 | |
Apple iOS and macOS | =10.13.6-security_update_2019-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-004 | |
Apple iOS and macOS | =10.13.6-security_update_2019-005 | |
Apple iOS and macOS | =10.13.6-security_update_2019-006 | |
Apple iOS and macOS | =10.13.6-security_update_2019-007 | |
Apple iOS and macOS | =10.13.6-security_update_2020-001 | |
Apple iOS and macOS | =10.13.6-security_update_2020-002 | |
Apple iOS and macOS | =10.13.6-security_update_2020-003 | |
Apple iOS and macOS | =10.13.6-security_update_2020-004 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2019-004 | |
Apple iOS and macOS | =10.14.6-security_update_2019-005 | |
Apple iOS and macOS | =10.14.6-security_update_2019-006 | |
Apple iOS and macOS | =10.14.6-security_update_2019-007 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-security_update_2020-004 | |
Apple iOS and macOS | =11.0.1 | |
tvOS | <14.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-10011 is a vulnerability in Model I/O that allows for an out-of-bounds read.
The severity of CVE-2020-10011 is not specified in the information provided.
CVE-2020-10011 affects iOS up to but excluding version 14.2, iPadOS up to but excluding version 14.2, tvOS up to but excluding version 14.2, macOS Catalina up to but excluding version 10.15.7, and macOS Big Sur up to but excluding version 11.0.1.
To fix CVE-2020-10011, update your software to the specified remedy versions provided by Apple.
You can find more information about CVE-2020-10011 on the Apple support website.