First published: Mon Dec 14 2020(Updated: )
ImageIO. An out-of-bounds read was addressed with improved input validation.
Credit: Xingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingWei Lin XingWei Lin Xingwei Lin Ant Security LightXingwei Lin Ant Security Light product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <12.0 | 12.0 |
Apple macOS Big Sur | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave | ||
Apple watchOS | <7.2 | 7.2 |
Apple tvOS | <14.3 | 14.3 |
Apple iOS | <14.3 | 14.3 |
Apple iPadOS | <14.3 | 14.3 |
Apple Icloud Windows | <12.0 | |
Apple iPadOS | <14.3 | |
Apple iPhone OS | <14.3 | |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.1.0 | |
Apple tvOS | <14.3 | |
Apple watchOS | <7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-29617 is a vulnerability in ImageIO that allows for an out-of-bounds read due to improved input validation.
Apple iOS, Apple iPadOS, Apple tvOS, Apple iCloud for Windows, Apple macOS Big Sur, Apple Catalina, Apple Mojave, and Apple watchOS versions up to exclusive are affected by CVE-2020-29617.
The severity of CVE-2020-29617 has not been provided.
Update to the latest version of Apple iOS, Apple iPadOS, Apple tvOS, Apple iCloud for Windows, Apple macOS Big Sur, Apple Catalina, Apple Mojave, or Apple watchOS to address the vulnerability.
You can find more information about CVE-2020-29617 on the Apple support page.