First published: Thu Nov 05 2020(Updated: )
libxml2. An integer overflow was addressed through improved input validation.
Credit: found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz found by OSS-Fuzz product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.11 | 12.11 |
Apple iCloud for Windows | <11.5 | 11.5 |
Apple macOS Big Sur | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave | ||
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Apple watchOS | <7.1 | 7.1 |
Apple tvOS | <14.2 | 14.2 |
Apple iOS | <14.2 | 14.2 |
Apple iPadOS | <14.2 | 14.2 |
Apple Icloud Windows | <11.5 | |
Apple Itunes Windows | <12.11 | |
Apple iPadOS | <14.2 | |
Apple iPhone OS | <14.2 | |
Apple macOS | >=11.0<11.0.1 | |
Apple tvOS | <14.2 | |
Apple watchOS | <7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-27911 is a vulnerability in libxml2 that allows for integer overflow through improved input validation.
CVE-2020-27911 affects Apple iOS up to version 14.2, Apple iPadOS up to version 14.2, Apple tvOS up to version 14.2, Apple iCloud for Windows up to version 11.5, Apple iTunes for Windows up to version 12.11, Apple macOS Big Sur up to version 11.0.1, Apple watchOS up to version 7.1, Apple macOS Big Sur up to version 11.1, Apple Catalina, and Apple Mojave.
To fix CVE-2020-27911, Apple users should update their software to the latest version available.
You can find more information about CVE-2020-27911 on the official Apple support page: [link](https://support.apple.com/en-us/HT211929) [link](https://support.apple.com/en-us/HT211933) [link](https://support.apple.com/en-us/HT211930)
The CWEs associated with CVE-2020-27911 are CWE-20 (Improper Input Validation) and CWE-190 (Integer Overflow or Wraparound).