First published: Thu Nov 12 2020(Updated: )
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. Processing a maliciously crafted image may lead to arbitrary code execution.
Credit: product-security@apple.com Hou JingYi @hjy79425575 Qihoo 360 CERTXingwei Lin Ant Security LightHou JingYi @hjy79425575 Qihoo 360 CERTXingwei Lin
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <11.0.1 | |
Apple Mac OS X | <11.1.0 | |
Apple macOS | <11.0.1 | 11.0.1 |
Apple macOS | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-27919 is a vulnerability in Image Processing that allows an out-of-bounds write.
macOS Big Sur versions up to exclusive 11.1, macOS Catalina, and macOS Mojave are affected by CVE-2020-27919.
To fix CVE-2020-27919, update your macOS Big Sur to version 11.1 or later.
You can find more information about CVE-2020-27919 on the official Apple support page: https://support.apple.com/en-us/HT212011
The CWE ID for CVE-2020-27919 is CWE-20.