First published: Mon Dec 14 2020(Updated: )
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
Credit: Alexandru-Vlad Niculae Google Project ZeroAlexandru-Vlad Niculae Google Project ZeroAlexandru-Vlad Niculae Google Project ZeroAlexandru-Vlad Niculae Google Project ZeroIvan Fratric Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <12.0 | 12.0 |
Apple macOS Big Sur | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave | ||
Apple watchOS | <7.2 | 7.2 |
Apple tvOS | <14.3 | 14.3 |
Apple iOS | <14.3 | 14.3 |
Apple iPadOS | <14.3 | 14.3 |
Apple Icloud Windows | <12.0 | |
Apple iPadOS | <14.3 | |
Apple iPhone OS | <14.3 | |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.1.0 | |
Apple tvOS | <14.3 | |
Apple watchOS | <7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-29611 is an out-of-bounds write vulnerability in ImageIO that has been addressed with improved bounds checking.
CVE-2020-29611 affects Apple iOS (up to version 14.3), Apple iPadOS (up to version 14.3), Apple tvOS(up to version 14.3), Apple iCloud for Windows (up to version 12.0), Apple macOS Big Sur (up to version 11.1), Apple Catalina, Apple Mojave, and Apple watchOS (up to version 7.2).
The severity of CVE-2020-29611 is not specified in the provided information.
Yes, the vulnerability has been addressed with improved bounds checking.
You can find more information about CVE-2020-29611 on the Apple support website.