First published: Tue Jan 28 2020(Updated: )
Crash Reporter. A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Credit: Csaba Fitzl @theevilbit product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.15.3 | |
Apple macOS Catalina | <10.15.3 | 10.15.3 |
Apple Mojave | ||
Apple High Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-3835 is a vulnerability in Crash Reporter that existed in the handling of symlinks.
The severity of CVE-2020-3835 is not specified in the provided information.
CVE-2020-3835 impacts macOS Catalina version 10.15.3 and below.
The impact of CVE-2020-3835 on Apple Mojave is not specified in the provided information.
The impact of CVE-2020-3835 on Apple High Sierra is not specified in the provided information.
To fix CVE-2020-3835, it is recommended to update to a version of macOS that includes the fix, as specified in the provided Apple support article.