First published: Mon Dec 14 2020(Updated: )
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
Credit: Ivan Fratric Google Project ZeroAlexandru-Vlad Niculae Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <14.3 | 14.3 |
Apple macOS | <11.1 | 11.1 |
macOS Catalina | ||
macOS Mojave | ||
Apple iOS, iPadOS, and watchOS | <14.3 | 14.3 |
Apple iOS, iPadOS, and watchOS | <14.3 | 14.3 |
Apple iOS, iPadOS, and watchOS | <7.2 | 7.2 |
Apple iCloud | <12.0 | 12.0 |
iCloud for Windows | <12.0 | |
Apple iOS, iPadOS, and watchOS | <14.3 | |
iStyle @cosme iPhone OS | <14.3 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2019-006 | |
Apple iOS and macOS | =10.14.6-security_update_2019-007 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-security_update_2020-004 | |
Apple iOS and macOS | =10.14.6-security_update_2020-005 | |
Apple iOS and macOS | =10.14.6-security_update_2020-006 | |
Apple iOS and macOS | =10.14.6-supplemental_update | |
Apple iOS and macOS | =10.14.6-supplemental_update_2 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
Apple iOS and macOS | >=11.0<11.1.0 | |
tvOS | <14.3 | |
Apple iOS, iPadOS, and watchOS | <7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-29611 is an out-of-bounds write vulnerability in ImageIO that has been addressed with improved bounds checking.
CVE-2020-29611 affects Apple iOS (up to version 14.3), Apple iPadOS (up to version 14.3), Apple tvOS(up to version 14.3), Apple iCloud for Windows (up to version 12.0), Apple macOS Big Sur (up to version 11.1), Apple Catalina, Apple Mojave, and Apple watchOS (up to version 7.2).
The severity of CVE-2020-29611 is not specified in the provided information.
Yes, the vulnerability has been addressed with improved bounds checking.
You can find more information about CVE-2020-29611 on the Apple support website.